Junglewise Threat Intelligence

CVE-2026-65458: Chouby Polylang sensitive data exposure

CVE-2026-65458 · Severity: medium · CVSS 4.3 · Published 2026-07-23

Executive brief

Polylang is a popular WordPress plugin used to create multilingual websites. A security flaw in versions 3.8.5 and earlier allows users with 'Contributor' level access to view sensitive system information that should normally be restricted. While this does not directly allow for site takeover, the exposed data could be used by an attacker to plan more sophisticated follow-up attacks.

Technical details

The Polylang plugin for WordPress is vulnerable to sensitive data exposure (CWE-497) in versions up to and including 3.8.5. This issue stems from improper restriction of sensitive system information within an unauthorized control sphere. An authenticated attacker with Contributor-level permissions can exploit this vulnerability via network requests to view data that is typically restricted to higher-privileged users. The vulnerability is addressed in version 3.8.6.

Affected products

  • Chouby (WP SYNTEX) Polylang <= 3.8.5

Timeline

  • 2026-06-24: disclosed: Reported by Ananda Dhakal via Patchstack
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: patched: Version 3.8.6 released to address the issue

References