Bogo

Bogo has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Missing Authorization, behind 1 of the records (100%).

The one issue recorded for Bogo has a vendor fix available, so running the current release closes it.

All of these findings were reported by Andrew Lacambra. Bogo is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Bogo vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.3CVE-2026-9013

Bogo <= 3.9.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via REST API

Read the full analysis

Vulnerability Records

1 records
Bogo banner
Latestv3.9.2
4.5(46)
90/100
Last Updated
2026-06-16 (2mo ago)
Active Installs
10,000+
Downloads
263,603
Requires WP
6.7+
Requires PHP
7.4+
Tested up to
WP 7.0.4
Created
2009-05-04 (18y ago)

Bogo is a straight-forward multilingual plugin for WordPress. The core of WordPress itself has the built-in localization capability so you can use the dashboard and theme in one language other than English. Bogo expands this capability to let you easily build a multilingual blog on a single WordPress install. Here are some technical details for those interested. Bogo plugin assigns one language per post. It plays nice with WordPress – Bogo does not create any additional custom table on your database, unlike some other plugins in this category. This design makes Bogo a solid, reliable and conflict-free multilingual plugin. Getting started with Bogo Install language packs First, install language packs for languages you use on the site. You can view and install language packs in the Language Packs screen (Languages > Language Packs). Select your language for admin screen Bogo lets each logged-in user select a language for their admin screen UI. Select a language from the menu on the Toolbar, or from the menu in the Profile screen (Users > Your Profile) if the Toolbar is invisible. Translate your posts and pages To create a translation post, go to the editor screen for the original post and find the Language box. Bogo does only make a copy of the post; translating the copied post is your task. Add language switcher widgets It would be useful for site visitors if you have a language switcher on your site. Bogo provides the Language Switcher widget in the Widgets screen (Appearance > Widgets). You can also use the [bogo] shortcode to put a language switcher inside a post content. If you want to use this shortcode in your theme’s template files, embed the following code into the template: <?php echo do_shortcode( '[bogo]' ); ?> Privacy notices With the default configuration, this plugin, in itself, does not: track users by stealth; write any user personal data to the database; send any data to external servers; use cookies.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C