Description
Missing Authorization vulnerability in WP SYNTEX Polylang polylang allows Retrieve Embedded Sensitive Data.This issue affects Polylang: from n/a through 3.8.7.
Published: 2026-10-05
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Sensitive Data Exposure
Action: Apply Patch
AI Analysis

Impact

Missing Authorization vulnerability in WP SYNTEX Polylang plugin allows retrieval of embedded sensitive data, resulting in potential exposure of confidential information.

Affected Systems

The vulnerability affects WP SYNTEX Polylang plugin versions from the current earliest revision through 3.8.7, inclusive. Any WordPress installation running a Polylang version at or below 3.8.7 is potentially impacted.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate risk. EPSS is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves sending a crafted HTTP request to an unprotected Polylang endpoint that returns sensitive content. Attackers with network access to the site can thus obtain confidential data without needing elevated permissions.

Generated by OpenCVE AI on October 5, 2026 at 12:20 UTC.

Remediation

Vendor Solution

Update the WordPress Polylang plugin to the latest available version (at least 3.8.8).


OpenCVE Recommended Actions

  • Upgrade the Polylang plugin to version 3.8.8 or later.
  • Review the plugin's configuration to ensure that only users with appropriate roles can access endpoints that could expose sensitive data.
  • Scan the website for any exposed data pages that might display sensitive information and remove or secure them.

Generated by OpenCVE AI on October 5, 2026 at 12:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in WP SYNTEX Polylang polylang allows Retrieve Embedded Sensitive Data.This issue affects Polylang: from n/a through 3.8.7.
Title WordPress Polylang plugin <= 3.8.7 - Sensitive Data Exposure vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-05T11:28:18.780Z

Reserved: 2026-04-07T10:59:15.735Z

Link: CVE-2026-39783

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T12:17:09.740

Modified: 2026-10-05T12:17:09.740

Link: CVE-2026-39783

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T12:30:15Z

Weaknesses