plugin

Polylang Vulnerabilities

4 known security issues reported for the Polylang WordPress plugin. Most recent disclosed Jul 22, 2026.

3 high 1 medium

Running Polylang on your site? Check whether your installed version is affected.

Scan your site free

Polylang <= 3.8.5 - Authenticated (Contributor+) Sensitive Information Exposure

medium

The Polylang plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
up to 3.8.5
Fixed in:
3.8.6
Disclosed:
Jul 22, 2026

CVE-2026-65458 on NVD →

Polylang <= 3.7.3 - Authenticated (Contributor+) PHP Object Injection

high

The Polylang plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.7.3 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable...

CVSS:
7.5
Affected:
up to 3.7.3
Fixed in:
3.7.4
Disclosed:
Oct 28, 2025

CVE-2025-64353 on NVD →

Polylang <= 2.5 - Cross-Site Request Forgery

high

The Polylang plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5. This is due to missing or incorrect nonce validation on the wp_insert_post_data() function. This makes it possible for unauthenticated attackers to duplicate media via a forged request granted they can t...

CVSS:
8.8
Affected:
up to 2.5.1
Fixed in:
2.5.1
Disclosed:
Jan 16, 2019

Polylang <= 1.5.1 - Cross-Site Scripting

high

Cross-site scripting (XSS) vulnerability in the Polylang plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to a user description. NOTE: some of these details are obtained from third party information.

CVSS:
7.1
Affected:
up to 1.5.2
Fixed in:
1.5.2
Disclosed:
Aug 1, 2014

CVE-2014-4855 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database