Sublanguage

Sublanguage has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 5.4 out of 10.

The most common weakness is Missing Authorization, behind 1 of the records (100%).

The one issue recorded for Sublanguage has a vendor fix available, so running the current release closes it.

All of these findings were reported by Abdi Pranata. Sublanguage is installed on roughly 700 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.6.7.

Strategic Overview

Avg CVSSMedium
5.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Sublanguage vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.4CVE-2023-36695

Sublanguage <= 2.9 - Missing Authorization

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
Sublanguage banner
Latestv2.12
4.6(31)
92/100
Last Updated
2025-12-08 (9mo ago)
Active Installs
700+
Downloads
28,572
Requires WP
4.5+
Requires PHP
0+
Tested up to
WP 6.6.7
Created
2015-07-03 (11y ago)

Sublanguage is a multilanguage plugin for wordpress. Concept no duplicated content (untranslated or untranslatable data inherits main language value) no additional database table (translation data is stored in post_meta) no markup added into content (unlike q-translate) no cookies (language is defined solely by URLs, better for SEO) Features [NEW] support for Gutenberg (beta feature) translation UI for posts content, title, permalink, excerpt and meta (for posts, pages and custom posts) translation UI for terms name, slug and description translation UI for attachments title, caption, description, alt and meta translation UI for nav menus translate localized text translate login, password change, etc. translatability: define which content is translatable or not URL rewrite: translate posts and terms permalinks and child pages path support revisions support multisite extendable Notes In version 2.9, a security vulnerability (“The plugin settings can be executed by lower privilleged (sic) user”) was reported for Sublanguage. In order to ease the fixing, we chose to permanently remove a few under-used features concerned by this exploit in v 2.10. Please write in the forum if you disagree with this choice. remove automatic upgrade from version 1.x (version 2.0 is now about 10 years old). remove a quick edit button in classic editor that was available width Tinymce Advanced plugin. remove the possibility to translate options (Options translated so far will still works as usual in the front-end, you just no longer can edit translations in the back-end). Documentation Plugin documentation is available on github Extensions Sublanguage Switcher Widget by Ralf Geschke Thanks uggur for Turkish translation

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C