Impact
The GPTranslate plugin exposes third‑party AI provider API keys in publicly accessible JavaScript assets, allowing unauthenticated users to recover a credential that grants billed account access. This weakness, classified as CWE-200, enables attackers to read sensitive data without authentication.
Affected Systems
The vulnerability affects the GPTranslate – Multilingual AI Translation Agent for WordPress plugin, all releases up to and including version 2.34.6. The default configuration using gpt‑3.5‑turbo in client mode is affected, as are all supported non‑DeepSeek providers. Only deepseek‑* models and gpt‑* models in server‑proxy mode correctly suppress key emission.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this by simply requesting any public page, downloading the plugin’s public JavaScript file, and applying the bundled inverse transformation to reveal the API key. If compromised, the attacker gains credentials that can be used to incur billing charges or access services associated with the API key.
OpenCVE Enrichment