CVE-2026-39783: WordPress Polylang plugin <= 3.8.7 - Sensitive Data Exposure vulnerability
Published Oct 5, 2026
·Updated
Missing Authorization vulnerability in WP SYNTEX Polylang polylang allows Retrieve Embedded Sensitive Data.This issue affects Polylang: from n/a through 3.8.7.
Affected Software
1 affected component
WP SYNTEX Polylang<=3.8.7
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WP SYNTEX Polylangto a version that resolves this vulnerability.Fixed in 3.8.8
Event History
Oct 5, 2026
CVE Published
via MITRE·11:28 AM
Data Sourced
via MITRE·11:28 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
The attacker needs network access to the affected site and low-level privileges. Exploitation is rated low complexity and does not require user interaction.
2
What is the expected impact if exploited?
The issue is rated as having low confidentiality impact. No integrity or availability impact is indicated.