{"id":"CVE-2026-89278","title":"The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.34.6 via the enqueue_frontend_scr…","summary":"The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.34.6 via the enqueue_frontend_scr…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-200"],"vendor":"john-dagelmore","product":"GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI","affected":["gptranslate_multilingual_ai_translation_agent_for_wordpress_translate_your_site_with_ai <= 2.34.6"],"published":"2026-09-18","updated":"2026-09-18","sourceUpdated":"2026-09-18T15:17:17.880","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-89278","references":[{"url":"https://plugins.trac.wordpress.org/browser/gptranslate/tags/2.34.6/gptranslate.php#L2142","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/gptranslate/tags/2.34.6/gptranslate.php#L2205","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3693232%40gptranslate&new=3693232%40gptranslate","label":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b7676362-4373-4c9a-b3cd-73fad9ff5477?source=cve","label":"security@wordfence.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-18T14:16:33.671871Z"},"epss":0.00438,"epssPercentile":0.35354,"ingestedAt":"2026-09-18T07:37:23.434Z","slug":"CVE-2026-89278","body":"## Overview\n\nThe GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.34.6 via the enqueue_frontend_scripts. This makes it possible for unauthenticated attackers to extract the plaintext third-party AI provider API key (OpenAI, DeepL, xAI/Grok, Gemini, Claude, or Google Cloud Translation) — a credential granting billed account access — by fetching any public page and applying the inverse transformation bundled in the plugin's own public JavaScript asset. This exposure affects the default configuration (gpt-3.5-turbo in client mode) and all supported non-DeepSeek providers; only deepseek-* models and gpt-* models configured in server-proxy mode correctly suppress key emission.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}