The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.34.6 via the enqueue_frontend_scripts. This makes it possible for unauthenticated attackers to extract the plaintext third-party AI provider API key (OpenAI, DeepL, xAI/Grok, Gemini, Claude, or Google Cloud Translation) — a credential granting billed account access — by fetching any public page and applying the inverse transformation bundled in the plugin's own public JavaScript asset. This exposure affects the default configuration (gpt-3.5-turbo in client mode) and all supported non-DeepSeek providers; only deepseek-* models and gpt-* models configured in server-proxy mode correctly suppress key emission.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 19 Sep 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
John-dagelmore
John-dagelmore gptranslate – Multilingual Ai Translation For Wordpress: Automatically Translate Websites Wordpress Wordpress wordpress |
|
| Vendors & Products |
John-dagelmore
John-dagelmore gptranslate – Multilingual Ai Translation For Wordpress: Automatically Translate Websites Wordpress Wordpress wordpress |
Fri, 18 Sep 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.34.6 via the enqueue_frontend_scripts. This makes it possible for unauthenticated attackers to extract the plaintext third-party AI provider API key (OpenAI, DeepL, xAI/Grok, Gemini, Claude, or Google Cloud Translation) — a credential granting billed account access — by fetching any public page and applying the inverse transformation bundled in the plugin's own public JavaScript asset. This exposure affects the default configuration (gpt-3.5-turbo in client mode) and all supported non-DeepSeek providers; only deepseek-* models and gpt-* models configured in server-proxy mode correctly suppress key emission. | |
| Title | GPTranslate <= 2.34.6 - Unauthenticated Sensitive Information Exposure in Public Frontend Inline Script | |
| Weaknesses | CWE-200 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-09-18T14:31:43.944Z
Reserved: 2026-09-11T11:15:53.864Z
Link: CVE-2026-89278
No data.
Status : Deferred
Published: 2026-09-18T07:16:51.050
Modified: 2026-09-18T15:17:17.880
Link: CVE-2026-89278
No data.
OpenCVE Enrichment
Updated: 2026-09-19T22:30:33Z
Weaknesses