{"api_version":"1","generated_at":"2026-08-11T11:30:09+00:00","cve":"CVE-2026-14548","urls":{"html":"https://cve.report/CVE-2026-14548","api":"https://cve.report/api/cve/CVE-2026-14548.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-14548","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-14548"},"summary":{"title":"Ray Enterprise Translation <= 1.7.3 - Subscriber+ Arbitrary API Token Update","description":"The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to overwrite the administrator-configured translation API token with an arbitrary value.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-08-11 06:17:13","updated_at":"2026-08-11 06:17:13"},"problem_types":["CWE-862 Missing Authorization"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/e1e0e945-db49-4e27-b143-ef3520a39db9/","name":"https://wpscan.com/vulnerability/e1e0e945-db49-4e27-b143-ef3520a39db9/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-14548","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14548","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"Ray Enterprise Translation","version":"affected 1.7.3 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Akshat Parikh (SN1PER)","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unknown","product":"Ray Enterprise Translation","vendor":"Unknown","versions":[{"lessThanOrEqual":"1.7.3","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Akshat Parikh (SN1PER)"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to overwrite the administrator-configured translation API token with an arbitrary value."}],"problemTypes":[{"descriptions":[{"description":"CWE-862 Missing Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-11T06:00:12.113Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/e1e0e945-db49-4e27-b143-ef3520a39db9/"}],"source":{"discovery":"EXTERNAL"},"title":"Ray Enterprise Translation <= 1.7.3 - Subscriber+ Arbitrary API Token Update","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-14548","datePublished":"2026-08-11T06:00:12.113Z","dateReserved":"2026-07-03T08:36:39.352Z","dateUpdated":"2026-08-11T06:00:12.113Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-11 06:17:13","lastModifiedDate":"2026-08-11 06:17:13","problem_types":["CWE-862 Missing Authorization"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"14548","Ordinal":"1","Title":"Ray Enterprise Translation <= 1.7.3 - Subscriber+ Arbitrary API ","CVE":"CVE-2026-14548","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"14548","Ordinal":"1","NoteData":"The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to overwrite the administrator-configured translation API token with an arbitrary value.","Type":"Description","Title":"Ray Enterprise Translation <= 1.7.3 - Subscriber+ Arbitrary API "}]}}}