CVE-2026-39783: Wp Syntex Polylang

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Missing Authorization vulnerability in WP SYNTEX Polylang polylang allows Retrieve Embedded Sensitive Data.This issue affects Polylang: from n/a through 3.8.7.

Affected products

  • Wp Syntex Polylang: up to and including 3.8.7

Published 2026-10-05. Last modified 2026-10-06.