Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
Threat Entry
Updated 2026-08-11
CVE-2026-14549 - Ray Enterprise Translation Plugin
The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to add or delete the site's configured languages.
PLUGIN
Ray Enterprise Translation
CVE-2026-14549
Risk Score
Threat Entry
Updated 2026-08-11
CVE-2026-14548 - Ray Enterprise Translation Plugin
The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to overwrite the administrator-configured translation API token with an arbitrary value.
PLUGIN
Ray Enterprise Translation
CVE-2026-14548
Risk Score
