
CVE-2026-14549 The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated u… https://www.cve.org/CVERecord?id=CVE-2026-14549
Post summary
The text discloses a capability/nonce check flaw in the Ray Enterprise Translation WordPress plugin that permits any authenticated user to exploit an unprotected AJAX action, but it provides no PoC, exploit, or patch details.
