Impact
The Ray Enterprise Translation plugin does not perform capability or nonce checks for an AJAX action that allows adding or deleting site languages. This flaw lets any authenticated WordPress user, including those with the Subscriber role, change language settings without proper authorization. The resulting modification can break the translation system, misrepresent content, and undermine the integrity of the site’s user experience.
Affected Systems
WordPress sites running the Ray Enterprise Translation plugin version 1.7.3 or earlier are affected. The vendor name is listed as Unknown:Ray Enterprise Translation and no specific patch version list is provided beyond the 1.7.3 ceiling. All installations of the plugin prior to a fixed release are at risk.
Risk and Exploitability
The vulnerability can be exploited by simply making an authenticated AJAX request; no network permissions or elevated privileges beyond existing authentication are required. The EPSS score is not available and the issue is not in the CISA KEV catalog, indicating no confirmed exploits yet but availability of exploitation paths. Given that the plugin omits nonce validation, cross‑site request forgery could also be possible, though this is inferred from the lack of protection rather than explicitly stated in the description. The CVSS score is not provided, yet the potential impact on configuration integrity and ease of exploitation suggests a serious risk.
OpenCVE Enrichment