Executive brief
The Smartcat Translator for WPML plugin for WordPress, which connects websites to professional translation services, contains a security flaw that allows unauthorized users to modify its settings. An attacker can remotely overwrite the plugin's API credentials, which could lead to a disruption of translation services or allow the attacker to hijack the connection to the translation provider. This could result in a loss of website functionality and potential financial or operational impact on translation workflows.
Technical details
The Smartcat Translator for WPML plugin for WordPress is vulnerable to a missing authorization check (CWE-862) within the 'routeData' REST endpoint. This vulnerability exists in all versions up to and including 3.1.77. The root cause is a missing capability check in the CallbackController and Router components, which allows unauthenticated network attackers to send requests that modify the plugin's configuration. Specifically, an attacker can overwrite critical Smartcat API credentials, including the account ID, API secret key, hub key, and host addresses. This can lead to a denial of service for translation features or the hijacking of the translation service integration. A patch is available in newer versions (changeset 3524382).
Affected products
- Smartcat Smartcat Translator for WPML up to, and including, 3.1.77
Timeline
- 2026-05-15: disclosed
- 2026-05-15: advisory
References
- https://plugins.trac.wordpress.org/browser/smartcat-wpml/trunk/includes/Controllers/CallbackController.php
- https://plugins.trac.wordpress.org/browser/smartcat-wpml/trunk/includes/Services/Plugin/Router.php
- https://plugins.trac.wordpress.org/changeset/3524382/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/6a9397ed-eddf-466b-b810-1e2f45afd291?source=cve