GPTranslate <= 2.34.6 - Unauthenticated Sensitive Information Exposure in Public Frontend Inline Script
Strategic Overview
- Status
- Patched in 2.34.7
- Affected Plugin
- GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI
- Affected Version
<= 2.34.6- CVSS
- 5.3Medium
- Weakness type
- CWE-200 · Exposure of Sensitive Information to an Unauthorized Actor
- CVE
CVE-2026-89278
At a glance
CVE-2026-89278 is a medium-severity Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the GPTranslate WordPress plugin, affecting versions <= 2.34.6. It carries a CVSS score of 5.3 (reachable over the network; low attack complexity). Exploitation requires no authentication. The issue is fixed in version 2.34.7; sites on affected versions should update now. Disclosed September 2026, reported by Supakiad S. (m3ez).
Vulnerability Overview
The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.34.6 via the enqueue_frontend_scripts. This makes it possible for unauthenticated attackers to extract the plaintext third-party AI provider API key (OpenAI, DeepL, xAI/Grok, Gemini, Claude, or Google Cloud Translation) — a credential granting billed account access — by fetching any public page and applying the inverse transformation bundled in the plugin's own public JavaScript asset. This exposure affects the default configuration (gpt-3.5-turbo in client mode) and all supported non-DeepSeek providers; only deepseek-* models and gpt-* models configured in server-proxy mode correctly suppress key emission.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no privileges on the target site, and no interaction from a victim user.
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Reaching this weakness in GPTranslate <= 2.34.6 takes no account at all. Sensitive information exposure means data the application intended to keep internal is returned to a caller who should not be able to see it.
The disclosed data — credentials, tokens, customer records or internal paths — is usually worth more as material for a follow-up attack than as an end in itself. For GPTranslate the fix is 2.34.7: builds <= 2.34.6 are affected, anything from 2.34.7 onward is not.
Remediation
Update to version 2.34.7, or a newer patched version
How does WordSec protect against this?
This one needs no account at all, which puts it outside what login hardening can reach; WordSec's login security narrows the account-level paths around it, and the firewall is what inspects the request itself. None of that substitutes for the fix: GPTranslate 2.34.7 closes this, and updating the plugin is the step that ends it.
- Login Security
- Alerts
External References
Related records
Other vulnerabilities in GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C