Polylang <= 3.8.5 - Authenticated (Contributor+) Sensitive Information Exposure
medium
The Polylang plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 3.8.5
- Fixed in:
- 3.8.6
- Disclosed:
- Jul 22, 2026
CVE-2026-65458 on NVD →
Polylang <= 3.7.3 - Authenticated (Contributor+) PHP Object Injection
high
The Polylang plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.7.3 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable...
- CVSS:
- 7.5
- Affected:
- up to 3.7.3
- Fixed in:
- 3.7.4
- Disclosed:
- Oct 28, 2025
CVE-2025-64353 on NVD →
Polylang <= 2.5 - Cross-Site Request Forgery
high
The Polylang plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5. This is due to missing or incorrect nonce validation on the wp_insert_post_data() function. This makes it possible for unauthenticated attackers to duplicate media via a forged request granted they can t...
- CVSS:
- 8.8
- Affected:
- up to 2.5.1
- Fixed in:
- 2.5.1
- Disclosed:
- Jan 16, 2019
Polylang <= 1.5.1 - Cross-Site Scripting
high
Cross-site scripting (XSS) vulnerability in the Polylang plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to a user description. NOTE: some of these details are obtained from third party information.
- CVSS:
- 7.1
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.2
- Disclosed:
- Aug 1, 2014
CVE-2014-4855 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database