What is CVE-2026-14549?
CVE-2026-14549 is a capability and nonce check vulnerability in the Ray Enterprise Translation WordPress plugin (through version 1.7.3). It allows any authenticated user, including Subscriber-level users, to add or delete the site's configured languages via an unprotected AJAX action. Updating the plugin to the latest version is strongly recommended.
Azərbaycanca: CVE-2026-14549, Ray Enterprise Translation WordPress plaginində (versiya 1.7.3 və aşağısı) tapılan bir səlahiyyət zəifliyidir. Hər hansı bir autentifikasiya olunmuş istifadəçi, o cümlədən abunəçilər, AJAX əməliyyatı vasitəsilə saytın konfiqurasiya olunmuş dillərini icazəsiz əlavə edə və ya silə bilər. Plagini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What level of users does the CVE-2026-14549 vulnerability in the Ray Enterprise Translation plugin affect?
This vulnerability allows any authenticated user, including Subscriber-level users, to be affected.
What unauthorized actions can be performed via the CVE-2026-14549 vulnerability?
It is possible to add or delete the site's configured languages without authorization via an unprotected AJAX action.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.