Junglewise Threat Intelligence

CVE-2026-65537: Themeisle Cyr to Lat reloaded broken access control

CVE-2026-65537 · Severity: medium · CVSS 4.3 · Published 2026-07-23

Vendors: Themeisle.

Executive brief

A security vulnerability exists in the Cyr to Lat reloaded WordPress plugin, which is used to automatically convert Cyrillic characters in links and filenames to Latin characters. A user with basic 'Subscriber' level access can bypass security checks to perform actions they should not be authorized to do. While the impact is considered low, it could allow unauthorized users to interfere with plugin settings or site metadata.

Technical details

The Cyr to Lat reloaded – transliteration of links and file names plugin for WordPress (versions 1.3.3 and below) contains a broken access control vulnerability. The issue stems from a missing authorization check (CWE-862) in a plugin function, which fails to verify if the requesting user has the appropriate administrative permissions. An attacker authenticated with a low-privilege account, such as a Subscriber, can exploit this to execute functions intended for higher-privileged users. The vulnerability is addressed in version 1.3.4.

Affected products

  • Themeisle Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3

Timeline

  • 2026-06-15: disclosed: Reported by Ananda Dhakal via Patchstack
  • 2026-07-23: advisory: NVD and Patchstack advisory published
  • 2026-07-23: patched: Version 1.3.4 released to address the issue

References