CVE-2026-0745 - Vulnerability Analysis
HighCVSS: 7.2Last Updated: February 14, 2026
WordPress User Language Switch - Server-Side Request Forgery
Overview
WordPress User Language Switch plugin <= 1.6.10 contains a server-side request forgery caused by missing URL validation in the 'download_language()' function, letting authenticated administrators make arbitrary web requests, exploit requires administrator privileges.
Severity & Score
Impact
Authenticated administrators can make arbitrary web requests, potentially querying and modifying internal service information.
Mitigation
Update to a version later than 1.6.10 or the latest available version.
References
- https://downloads.wordpress.org/plugin/user-language-switch.zip
- https://plugins.trac.wordpress.org/browser/user-language-switch/tags/1.6.10/uls-options.php#L451
- https://plugins.trac.wordpress.org/browser/user-language-switch/trunk/uls-options.php#L451
- https://wordpress.org/plugins/user-language-switch/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/4d8d15be-6a7b-485e-a338-ccf1a6eb226c?source=cve
Social Media Activity(2 posts)
SSRF vulnerability (HIGH, CVE-2026-0745) in WordPress User Language Switch plugin (all versions). Admin-level users can access internal services. Audit, limit admin access, and monitor for suspicious requests. No patch yet. https://radar.offseq.com/threat/cve-2026-0745-cwe-918-server-side-request-forgery--d2649c34 #OffSeq #WordPress #SSRF
View original postSSRF vulnerability (HIGH, CVE-2026-0745) in WordPress User Language Switch plugin (all versions). Admin-level users can access internal services. Audit, limit admin access, and monitor for suspicious requests. No patch yet. https://radar.offseq.com/threat/cve-2026-0745-cwe-918-server-side-request-forgery--d2649c34 #OffSeq #WordPress #SSRF
View original postGitHub Repositories(1 repo)
Related Resources
Details
- CVE ID
- CVE-2026-0745
- Severity
- High
- CVSS Score
- 7.2
- Type
- server_side_request_forgery
- Status
- new
- EPSS
- 3.0%
- Social Posts
- 2
CWE
- CWE-918
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N