Sceawere

Vulnerability Detail

CVE-2026-107419UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Missing Authorization in AI Translation

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
4h ago
Vendor
Cool Plugins
Product
AI Translation for Polylang
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Missing Authorization vulnerability in Cool Plugins AI Translation for Polylang automatic-translations-for-polylang allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Translation for Polylang: from n/a through 1.6.2.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-10-09T12:17:08.870Z",
  "pubdate": "2026-10-09T12:17:08.870Z",
  "executiveSummary": "The AI Translation for Polylang plugin is susceptible to a Missing Authorization vulnerability, classified under improper access control. This security flaw allows unauthenticated or unauthorized remote actors to perform restricted actions within the plugin's environment.\nThe vulnerability affects versions from n/a through 1.6.2. By exploiting incorrectly configured access control checks, an attacker can manipulate plugin functionality without requiring legitimate administrative privileges.\nThe risk implication is significant as it undermines the security boundary of the WordPress installation, potentially allowing unauthorized translation operations or configuration changes. Successful exploitation does not require advanced technical capabilities, provided the attacker can interact with the vulnerable plugin endpoints.\nOrganizations using this plugin are exposed to unauthorized access, necessitating immediate attention to software updates and access management policies.",
  "technicalDetails": "The vulnerability stems from the absence of appropriate capability checks within the plugin's request handling logic. Specifically, the plugin fails to verify user permissions before executing sensitive operations associated with automatic translation tasks.\nIn the WordPress environment, sensitive administrative or plugin-specific functions must be guarded by permission checks—typically utilizing functions such as current_user_can()—to ensure the requester possesses the required authorization, such as 'manage_options' or other administrative roles.\nThe root cause is an insecure implementation of access control where the plugin processes requests to perform translations or update settings without enforcing these security checks. An attacker can craft HTTP requests targeting specific plugin endpoints (e.g., AJAX actions or REST API routes) and successfully trigger backend operations that should be restricted.\nThe attack flow involves the following steps: 1. Identification of the vulnerable endpoint within the 'AI Translation for Polylang' plugin. 2. Crafting of a malicious request designed to trigger the unauthorized function. 3. Transmission of the request to the target server. Because the plugin does not validate the security context or user identity, the server processes the request as if it were authorized, executing the requested action.\nThis vulnerability is classified as a failure in access control, allowing unauthorized users to interact with features intended only for administrators. The impact includes the potential for unauthorized usage of the translation service, configuration modification, or other side effects depending on the functionality exposed through the unauthenticated endpoint.\nExploitation requires no special authentication, as the flaw resides in the lack of check for such authentication. The exposure is network-based, meaning any remote attacker capable of sending HTTP requests to the vulnerable WordPress site can attempt exploitation. Post-exploitation impact varies but generally includes unauthorized utilization of plugin resources and the potential for further manipulation of the plugin's configuration."
}
CVE-2026-107419: Missing Authorization in AI Translation (MEDIUM Severity, CVSS: 5.4) | Sceawere