Executive brief
Falang multilanguage is a WordPress plugin used to manage and display content in multiple languages. A security flaw in versions 1.4.2 and earlier allows a user with basic 'Subscriber' access to elevate their permissions, potentially gaining full administrative control over the website. This could lead to unauthorized data access, website defacement, or a total service outage.
Technical details
A privilege escalation vulnerability exists in the Falang multilanguage plugin for WordPress (versions <= 1.4.2) due to incorrect privilege assignment (CWE-266). An authenticated attacker with a low-privileged account, such as a Subscriber, can exploit this flaw to escalate their privileges to a higher level, potentially reaching Administrator status. The attack is carried out over the network and does not require user interaction. This vulnerability was patched in version 1.4.3.
Affected products
- sbouey Falang multilanguage <= 1.4.2
Timeline
- 2026-05-08: other: Reported by ParkHyunWoo
- 2026-06-16: advisory: Patchstack advisory published
- 2026-06-17: disclosed: NVD publication date