Junglewise Threat Intelligence

CVE-2026-54805: Falang multilanguage privilege escalation in WordPress plugin

CVE-2026-54805 · Severity: high · CVSS 8.8 · Published 2026-06-17

Executive brief

Falang multilanguage is a WordPress plugin used to manage and display content in multiple languages. A security flaw in versions 1.4.2 and earlier allows a user with basic 'Subscriber' access to elevate their permissions, potentially gaining full administrative control over the website. This could lead to unauthorized data access, website defacement, or a total service outage.

Technical details

A privilege escalation vulnerability exists in the Falang multilanguage plugin for WordPress (versions <= 1.4.2) due to incorrect privilege assignment (CWE-266). An authenticated attacker with a low-privileged account, such as a Subscriber, can exploit this flaw to escalate their privileges to a higher level, potentially reaching Administrator status. The attack is carried out over the network and does not require user interaction. This vulnerability was patched in version 1.4.3.

Affected products

  • sbouey Falang multilanguage <= 1.4.2

Timeline

  • 2026-05-08: other: Reported by ParkHyunWoo
  • 2026-06-16: advisory: Patchstack advisory published
  • 2026-06-17: disclosed: NVD publication date

References