CVE-2026-89278

GPTranslate <= 2.34.6 - Unauthenticated Sensitive Information Exposure in Public Frontend Inline Script

2026-09-17 00:00
Supakiad S. (m3ez)

Strategic Overview

Status
Patched in 2.34.7
Affected Version
<= 2.34.6
CVSS
5.3Medium
Weakness type
CWE-200 · Exposure of Sensitive Information to an Unauthorized Actor
CVE
CVE-2026-89278
View all GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI vulnerabilities

At a glance

CVE-2026-89278 is a medium-severity Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the GPTranslate WordPress plugin, affecting versions <= 2.34.6. It carries a CVSS score of 5.3 (reachable over the network; low attack complexity). Exploitation requires no authentication. The issue is fixed in version 2.34.7; sites on affected versions should update now. Disclosed September 2026, reported by Supakiad S. (m3ez).

Vulnerability Overview

The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.34.6 via the enqueue_frontend_scripts. This makes it possible for unauthenticated attackers to extract the plaintext third-party AI provider API key (OpenAI, DeepL, xAI/Grok, Gemini, Claude, or Google Cloud Translation) — a credential granting billed account access — by fetching any public page and applying the inverse transformation bundled in the plugin's own public JavaScript asset. This exposure affects the default configuration (gpt-3.5-turbo in client mode) and all supported non-DeepSeek providers; only deepseek-* models and gpt-* models configured in server-proxy mode correctly suppress key emission.

Technical Analysis

The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no privileges on the target site, and no interaction from a victim user.

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Reaching this weakness in GPTranslate <= 2.34.6 takes no account at all. Sensitive information exposure means data the application intended to keep internal is returned to a caller who should not be able to see it.

The disclosed data — credentials, tokens, customer records or internal paths — is usually worth more as material for a follow-up attack than as an end in itself. For GPTranslate the fix is 2.34.7: builds <= 2.34.6 are affected, anything from 2.34.7 onward is not.

Remediation

Update to version 2.34.7, or a newer patched version

How does WordSec protect against this?

This one needs no account at all, which puts it outside what login hardening can reach; WordSec's login security narrows the account-level paths around it, and the firewall is what inspects the request itself. None of that substitutes for the fix: GPTranslate 2.34.7 closes this, and updating the plugin is the step that ends it.

  • Login Security
  • Alerts

External References

Related records

Other vulnerabilities in GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C