Description
Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.
Published: 2026-07-23
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a broken access control flaw in the WordPress Cyr to Lat reloaded – transliteration of links and file names plugin from Themeisle. It allows an authenticated user with the Subscriber role to bypass the access checks that should restrict plugin functionality. The weakness is identified as CWE‑862. The result can compromise the confidentiality, integrity, or availability of the site by letting a Subscriber perform actions that are normally reserved for higher‑privileged roles.

Affected Systems

The vulnerability affects WordPress sites that have installed any version of the Cyr to Lat reloaded – transliteration of links and file names plugin up to and including 1.3.3. The plugin is an individual WordPress plugin, so any site running these versions is exposed. No additional operating system or platform details are provided.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity. EPSS shows less than 1% probability of exploitation, and the vulnerability is not listed in CISA KEV. The likely attack vector is through legitimate plugin use by an authenticated Subscriber; the flaw is tied to role checks within the plugin code. The potential impact is limited to the scope of actions that the plugin exposes beyond normal Subscriber permissions, with low exploitation likelihood based on the given metrics.

Generated by OpenCVE AI on August 3, 2026 at 21:46 UTC.

Remediation

Vendor Solution

Update the WordPress Cyr to Lat reloaded – transliteration of links and file names Plugin to the latest available version (at least 1.3.4).


OpenCVE Recommended Actions

  • Update the Cyr to Lat reloaded – transliteration of links and file names plugin to version 1.3.4 or later.
  • If the update cannot be applied immediately, deactivate the plugin to remove the risk until the fix is available.
  • Restrict the Subscriber role’s access to the plugin’s functionality or remove the role entirely to limit potential misuse.

Generated by OpenCVE AI on August 3, 2026 at 21:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Themeisle
Themeisle cyr To Lat Reloaded – Transliteration Of Links And File Names
Wordpress
Wordpress wordpress
Vendors & Products Themeisle
Themeisle cyr To Lat Reloaded – Transliteration Of Links And File Names
Wordpress
Wordpress wordpress
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.
Title WordPress Cyr to Lat reloaded – transliteration of links and file names plugin <= 1.3.3 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Themeisle Cyr To Lat Reloaded – Transliteration Of Links And File Names
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T15:22:08.465Z

Reserved: 2026-07-22T08:54:12.816Z

Link: CVE-2026-65537

cve-icon Vulnrichment

Updated: 2026-07-23T15:22:02.077Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:46.737

Modified: 2026-07-23T16:17:52.597

Link: CVE-2026-65537

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:00:04Z

Weaknesses