Description
The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.34.6 via the enqueue_frontend_scripts. This makes it possible for unauthenticated attackers to extract the plaintext third-party AI provider API key (OpenAI, DeepL, xAI/Grok, Gemini, Claude, or Google Cloud Translation) — a credential granting billed account access — by fetching any public page and applying the inverse transformation bundled in the plugin's own public JavaScript asset. This exposure affects the default configuration (gpt-3.5-turbo in client mode) and all supported non-DeepSeek providers; only deepseek-* models and gpt-* models configured in server-proxy mode correctly suppress key emission.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Exposure
Action: Apply Patch
AI Analysis

Impact

The GPTranslate plugin exposes third‑party AI provider API keys in publicly accessible JavaScript assets, allowing unauthenticated users to recover a credential that grants billed account access. This weakness, classified as CWE-200, enables attackers to read sensitive data without authentication.

Affected Systems

The vulnerability affects the GPTranslate – Multilingual AI Translation Agent for WordPress plugin, all releases up to and including version 2.34.6. The default configuration using gpt‑3.5‑turbo in client mode is affected, as are all supported non‑DeepSeek providers. Only deepseek‑* models and gpt‑* models in server‑proxy mode correctly suppress key emission.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this by simply requesting any public page, downloading the plugin’s public JavaScript file, and applying the bundled inverse transformation to reveal the API key. If compromised, the attacker gains credentials that can be used to incur billing charges or access services associated with the API key.

Generated by OpenCVE AI on September 19, 2026 at 20:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GPTranslate to the latest version that removes API key exposure (≥2.34.7).
  • Configure the plugin to use server‑proxy mode or deepseek‑* models so that no key is sent to the client.
  • Add a Web Application Firewall rule or CSP header to block or filter the plugin’s public JavaApplication asset from being served to unauthenticated users.

Generated by OpenCVE AI on September 19, 2026 at 20:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared John-dagelmore
John-dagelmore gptranslate – Multilingual Ai Translation For Wordpress: Automatically Translate Websites
Wordpress
Wordpress wordpress
Vendors & Products John-dagelmore
John-dagelmore gptranslate – Multilingual Ai Translation For Wordpress: Automatically Translate Websites
Wordpress
Wordpress wordpress

Fri, 18 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.34.6 via the enqueue_frontend_scripts. This makes it possible for unauthenticated attackers to extract the plaintext third-party AI provider API key (OpenAI, DeepL, xAI/Grok, Gemini, Claude, or Google Cloud Translation) — a credential granting billed account access — by fetching any public page and applying the inverse transformation bundled in the plugin's own public JavaScript asset. This exposure affects the default configuration (gpt-3.5-turbo in client mode) and all supported non-DeepSeek providers; only deepseek-* models and gpt-* models configured in server-proxy mode correctly suppress key emission.
Title GPTranslate <= 2.34.6 - Unauthenticated Sensitive Information Exposure in Public Frontend Inline Script
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

John-dagelmore Gptranslate – Multilingual Ai Translation For Wordpress: Automatically Translate Websites
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-18T14:31:43.944Z

Reserved: 2026-09-11T11:15:53.864Z

Link: CVE-2026-89278

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-18T07:16:51.050

Modified: 2026-09-18T15:17:17.880

Link: CVE-2026-89278

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:30:33Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor