Polylang

Polylang has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2014 and 2026; all 4 are fixed as of September 2026. Their average CVSS score is 6.9, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 3 high.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (25%). Other recurring categories include Cross-Site Scripting, Deserialization Of Untrusted Data.

Every one of the 4 issues recorded for Polylang has a vendor fix available, so running the current release closes all known holes.

3 independent researchers contributed these findings, one record each. Polylang is installed on roughly 800,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
6.9/ 10
Patch Coverage100%
Open

0

Fixed

4

Get automatic notifications for all Polylang vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8

Polylang <= 2.5 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

4 records
Polylang banner
Latestv3.8.8

Polylang

Chouby

Author

Chouby

4.7(2,984)
94/100
Last Updated
2026-09-07 (6d ago)
Active Installs
800,000+
Downloads
28,580,589
Requires WP
6.5+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2011-09-22 (15y ago)

With Polylang fully integrated to WordPress and using only its built-in core features (taxonomies), keep steady performances on your site and create a multilingual site featuring from just one extra language to 10 or more depending on your needs. There is no limit in the number of languages added and WordPress’ language packs are automatically downloaded when ready. Features Depending on the type of site you have built or are planning to build, a combination of plugins from the list below might be of interest. All plugins include a wizard allowing to setup them in just a few clicks. Polylang Polylang and Polylang Pro share the same core providing features such as: Translating posts, pages, media, categories, post tags, custom post types and taxonomies, RSS feeds; RTL scripts are supported. The language is either set by the language code in URL, or you can use a different sub-domain or domain per language. Automatic copy of categories, post tags and other metas when creating a new post or page translation. Translating classic menus and classic widgets. Also accessible with Site Editor Classic Features in block themes. Customizable language switchers available as blocks, classic widget or classic navigation menu item. Compatibility with Yoast SEO. Polylang Pro Helps optimizing the time spent translating your site with some very useful extra features such as: Better integration in the new Block Editor. Language options available in the widget block editor. Template parts translatable in the site editor (FSE). Duplicate and/or synchronize content across post translations. Improved compatibility with other plugins such as ACF Pro. Share the same URL slug for posts or terms across languages. Translate URL slugs for categories, author bases, custom post types and more… Machine translation with DeepL. Export and import of content in XLIFF format for outsourced professional translation. Access to a Premium Support for personalized assistance. Polylang for WooCommerce Add-on for the compatibility with WooCommerce which provides features such as: Translating WooCommerce pages (shop, check-out, cart, my account), product categories and global attribute terms directly in the WooCommerce interface. Translating WooCommerce e-mails and sending them to customers in their language. Products metadata synchronization. Compatibility with the native WooCommerce CSV import & export tool. Compatibility with popular plugins such as WooCommerce Subscriptions, Product Bundles, WooCommerce Bookings, Shipment Tracking and more. Ability to use the WooCommerce REST API (available with Polylang Pro). Access to a Premium Support for personalized assistance. Switching from WPML? WPML to Polylang allows migrating from WPML to Polylang in a few clicks. Credits Thanks a lot to all translators who help translating Polylang. Thanks a lot to Alex Lopez for the design of the logo. Most of the flags included with Polylang are coming from famfamfam and are public domain. Wherever third party code has been used, credit has been given in the code’s comments.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C