The Polylang Plugin Project maintains a WordPress multilingual plugin focused on language and translation management within WordPress sites. Observed vulnerability disclosures center on cross-site scripting issues in web page generation and output handling, a pattern typical of user-facing content-management features where input sanitization and output encoding demand careful attention. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Polylang Plugin Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-4855MEDIUM Cross-site scripting (XSS) vulnerability in the Polylang plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to a u | Jul 10, 2014 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Polylang Plugin Project.
Media articles that mention a CVE ID that affects a product developed by Polylang Plugin Project — matched by CVE ID, not by vendor name.