CVE-2026-107419: WordPress AI Translation for Polylang plugin <= 1.6.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in Cool Plugins AI Translation for Polylang automatic-translations-for-polylang allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Translation for Polylang: from n/a through 1.6.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress AI Translation for Polylangto a version that resolves this vulnerability.Fixed in 1.6.3
Event History
Frequently Asked Questions
Which deployments are affected?
AI Translation for Polylang versions through 1.6.2 are affected. The available data does not identify a safe fixed version.
What level of access does an attacker need?
The CVSS vector indicates that exploitation requires low-level privileges (PR:L). It is remotely exploitable with low attack complexity and does not require user interaction.
What is the likely impact of successful exploitation?
The stated impact is low integrity and low availability impact, with no confidentiality impact. The scope is unchanged.