Sublanguage
Sublanguage has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 5.4 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Sublanguage has a vendor fix available, so running the current release closes it.
All of these findings were reported by Abdi Pranata. Sublanguage is installed on roughly 700 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.6.7.
CVE-2023-36695Sublanguage <= 2.9 - Missing Authorization
Read the full analysisVulnerability Records

Sublanguage
Author
maximeschoeni
Sublanguage is a multilanguage plugin for wordpress. Concept no duplicated content (untranslated or untranslatable data inherits main language value) no additional database table (translation data is stored in post_meta) no markup added into content (unlike q-translate) no cookies (language is defined solely by URLs, better for SEO) Features [NEW] support for Gutenberg (beta feature) translation UI for posts content, title, permalink, excerpt and meta (for posts, pages and custom posts) translation UI for terms name, slug and description translation UI for attachments title, caption, description, alt and meta translation UI for nav menus translate localized text translate login, password change, etc. translatability: define which content is translatable or not URL rewrite: translate posts and terms permalinks and child pages path support revisions support multisite extendable Notes In version 2.9, a security vulnerability (“The plugin settings can be executed by lower privilleged (sic) user”) was reported for Sublanguage. In order to ease the fixing, we chose to permanently remove a few under-used features concerned by this exploit in v 2.10. Please write in the forum if you disagree with this choice. remove automatic upgrade from version 1.x (version 2.0 is now about 10 years old). remove a quick edit button in classic editor that was available width Tinymce Advanced plugin. remove the possibility to translate options (Options translated so far will still works as usual in the front-end, you just no longer can edit translations in the back-end). Documentation Plugin documentation is available on github Extensions Sublanguage Switcher Widget by Ralf Geschke Thanks uggur for Turkish translation
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C