Low · 3.3 WordPress CVE-2026-39783
Polylang WordPress Plugin: Missing Authorization Vulnerability Allows Access to Sensitive Data (CVE-2026-39783)
A missing authorization vulnerability in the Polylang WordPress plugin, affecting versions through 3.8.7, could allow a lower-privileged authenticated user to retrieve embedded sensitive data. The issue is tracked as CVE-2026-39783 and is fixed in version 3.8.8.
AI summary
WP SYNTEX's Polylang, a widely used WordPress plugin for multilingual sites, is affected by a missing authorization vulnerability tracked as CVE-2026-39783. The issue affects versions of Polylang up through 3.8.7 and allows retrieval of embedded sensitive data. A fixed version, 3.8.8, is referenced in advisory data.
What happened
A missing authorization vulnerability (CWE-862) was identified in the Polylang WordPress plugin. The flaw allows retrieval of embedded sensitive data due to insufficient authorization checks. The issue affects Polylang versions through 3.8.7.
Technical cause
The vulnerability is classified under CWE-862 (Missing Authorization). This means the plugin fails to properly verify that a user is authorized to access certain data before returning it, which in this case allows retrieval of embedded sensitive data. No further technical details about the specific code path or endpoint are provided in the available advisory data.
Why it matters
The vulnerability has a CVSS base score of 4.3 (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N), indicating a network-exploitable issue with low attack complexity. It requires low privileges and no user interaction, but the confidentiality impact is limited to low, with no impact on integrity or availability. This means an attacker would need some level of authenticated access to a site running the affected plugin to exploit the flaw and retrieve embedded sensitive data.
Who is affected
Any WordPress site running the Polylang plugin in an affected version (through 3.8.7) is potentially affected. Polylang is used on a large number of WordPress installations for multilingual site management, which increases the overall exposure footprint even though the vulnerability itself requires authenticated access.
Affected versions
Polylang versions up through 3.8.7 are affected. Version 3.8.8 is referenced as the fixed version in the affected-range data provided.
Fixes and mitigation
The fact package indicates an affected-range record listing 3.8.8 as the version where the issue is fixed. However, the advisory-level 'fix_available' field is marked as false, which conflicts with this affected-range data. This discrepancy could not be resolved from the available facts, and we flag it explicitly below as an editorial warning. Site owners should verify directly with the plugin changelog or vendor whether 3.8.8 or a later release resolves this issue before relying on this information.
Recommended action
WordPress site administrators running Polylang should check their installed version and consult the official plugin changelog to confirm whether an update to 3.8.8 or later is available and addresses CVE-2026-39783. Given the conflicting fix-availability signal in the source data, we recommend independently confirming fix status before taking action, and monitoring the WordPress.org plugin repository for further updates.
PatchBriefing score
3.3 / 10 · Low
Official CVSS: 4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Why this score
This issue carries a Patchwire score of 3.3, reflecting a moderate-to-low risk profile. The CVSS base score of 4.3 contributes most of the score, reflecting a network-exploitable but low-impact confidentiality issue. There is no known exploitation in the wild, no public exploit code, and the vulnerability requires authenticated access with low privileges, which reduces its immediate risk. The lack of a confirmed fix and Polylang's large install base add a small amount to the overall score, but the absence of active exploitation, public exploit availability, or unauthenticated remote access keeps the score in a moderate-to-low range.
Affected versions
- Polylang < 3.8.8
- vulnerable
Reported fixes
The fact package indicates an affected-range record listing 3.8.8 as the version where the issue is fixed. However, the advisory-level 'fix_available' field is marked as false, which conflicts with this affected-range data. This discrepancy could not be resolved from the available facts, and we flag it explicitly below as an editorial warning. Site owners should verify directly with the plugin changelog or vendor whether 3.8.8 or a later release resolves this issue before relying on this information.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
WPVulnerability database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email