Add Polylang support for Customizer
Add Polylang support for Customizer has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Add Polylang support for Customizer has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2026.
All of these findings were reported by Nabil Irawan. Add Polylang support for Customizer is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.1.12.
CVE-2026-22462Add Polylang support for Customizer <= 1.4.5 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

Add Polylang support for Customizer
Author
richardevcom
Add Polylang support for Customizer This plugin adds Polylang support for WordPress Customizer. Support We provide direct support via our Frontbee Discord server Features Language switcher in Customizer. Localized theme_mods and options for both default and custom made Customizer values. Enable/disable forcing “The language is set from content” setting in Language->Settings->URL modifications Prerequisite Polylang must be installed and activated. Languages must be set in Admin > Languages. If you have a static front page: Create a front page per each language. Select the front page in Admin > Settings > Reading per language. Expect customizer to use setting type = theme_mod (default) as in: $wp_customize->add_setting( ‘setting_id’, [ ‘type’ => ‘theme_mod’, ] ); License This plugin is licensed under the GPL v2 or later. This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License, version 2, as published by the Free Software Foundation. This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with this program; if not, write to the Free Software Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA A copy of the license is included in the root of the plugin’s directory. The file is named LICENSE. Important Notes Licensing This plugin is licensed under the GPL v2 or later; however, if you opt to use third-party code that is not compatible with v2, then you may need to switch to using code that is GPL v3 compatible. Credits Original solution made by @soderlind is available here. Share some love! This is WordPress plugin version of his solution.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C