Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Chouby Polylang and Chouby Polylang Pro allows Retrieve Embedded Sensitive Data.

This issue affects Polylang: through 3.8.5; Polylang Pro: through 3.8.5.
Published: 2026-07-23
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Chouby Polylang and Polylang Pro plugins up to version 3.8.5 exposes sensitive system information to an unauthorized control sphere, allowing the retrieval of embedded sensitive data. An attacker with access to the affected WordPress installation can exploit the plugin to read data that should not be publicly or externally available. The weakness is classified as CWE-497, indicating information disclosure beyond the intended scope.

Affected Systems

WordPress installations that run the Polylang plugin from Chouby at version 3.8.5 or earlier are affected. The issue is fixed in later releases, so any site using a post-3.8.5 version is no longer vulnerable.

Risk and Exploitability

The CVSS score of 4.3 indicates a low severity. An EPSS score of less than 1% shows probability of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the WordPress administration interface or actions involving contributors, implying that an attacker would need access to a WordPress site that hosts the vulnerable plugin. It is inferred from the description that the attack would require either contributor privileges or the ability to manipulate contributor data.

Generated by OpenCVE AI on August 6, 2026 at 11:50 UTC.

Remediation

Vendor Solution

Update the WordPress Polylang plugin to the latest available version (at least 3.8.6).


OpenCVE Recommended Actions

  • Update the Polylang plugin to version 3.8.6 or later.
  • Update the Polylang Pro plugin to version 3.8.6 or later.
  • If a patch cannot be applied immediately, disable or remove contributor users until the plugin is updated.
  • Review the site for any exposed contributor data and adjust privacy settings or remove public endpoints that expose contributor information.

Generated by OpenCVE AI on August 6, 2026 at 11:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description Contributor Sensitive Data Exposure in Polylang <= 3.8.5 versions. Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Chouby Polylang and Chouby Polylang Pro allows Retrieve Embedded Sensitive Data. This issue affects Polylang: through 3.8.5; Polylang Pro: through 3.8.5.
Title WordPress Polylang plugin <= 3.8.5 - Sensitive Data Exposure vulnerability WordPress Polylang and Polylang Pro plugins <= 3.8.5 - Sensitive Data Exposure vulnerability

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Chouby
Chouby polylang
Wordpress
Wordpress wordpress
Vendors & Products Chouby
Chouby polylang
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Contributor Sensitive Data Exposure in Polylang <= 3.8.5 versions.
Title WordPress Polylang plugin <= 3.8.5 - Sensitive Data Exposure vulnerability
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Chouby Polylang
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T09:51:46.458Z

Reserved: 2026-07-22T08:53:17.417Z

Link: CVE-2026-65458

cve-icon Vulnrichment

Updated: 2026-07-23T14:47:07.472Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:38.357

Modified: 2026-08-06T10:16:44.363

Link: CVE-2026-65458

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T12:00:06Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere