CVE-2025-10008

MEDIUM

Translate Weglot <5.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Translate WordPress and go Multilingual – Weglot plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'clean_options' function in all versions up to, and including, 5.1. This makes it possible for unauthenticated attackers to delete limited transients that contain cached plugin options.

Scores

CVSS v3 5.3
EPSS 0.0024
EPSS Percentile 15.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
remyb92/Translate WordPress and go Multilingual – Weglot < 5.1
remyb92/Translate WordPress with Weglot – Multilingual AI Translation < 5.1
Published Oct 30, 2025
Tracked Since Feb 18, 2026