Description
The Translate WordPress and go Multilingual – Weglot plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'clean_options' function in all versions up to, and including, 5.1. This makes it possible for unauthenticated attackers to delete limited transients that contain cached plugin options.
Problem types
Product status
Any version
Timeline
| 2025-09-23: | Vendor Notified |
| 2025-10-29: | Disclosed |
Credits
Nguyen Ngoc Quang Bach
References
www.wordfence.com/...-fe97-4588-a084-64f502a40c51?source=cve
plugins.trac.wordpress.org/.../front/class-clean-options.php
plugins.trac.wordpress.org/changeset/3383165/