Vulnerability  ·  2026-10-10

AI Translation for Polylang WordPress plugin missing authorization (CVSS 5.4)

VulnerabilityLow impactGlobalCVE-2026-107419
Verified via NVD REST API (published 2026-10-09, Patchstack): missing authorization in the AI Translation for Polylang plugin up to 1.6.2 allows exploiting incorrectly configured access control security levels (CWE-862); fixed in 1.6.3.
AI translation plugins hold API-key plumbing and content-administration rights; a broken-access-control hole lets non-privileged users trigger AI translation actions and access resources they should not, a common high-blast-radius issue for AI WordPress plugins.
Authenticated user exploits missing authorization (CWE-862) in the AI translation plugin's incorrectly configured access-control security levels to invoke functions beyond their role.
Cool Plugins AI Translation for Polylang (automatic-translations-for-polylang) <= 1.6.2
Upgrade to 1.6.3 when available; Patchstack entry: https://patchstack.com/database/wordpress/plugin/automatic-translations-for-polylang/vulnerability/wordpress-ai-translation-for-polylang-plugin-1-6-2-broken-access-control-vulnerability
NVD CVE-2026-107419Patchstack
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →