Stored Cross-Site Scripting in TranslatePress Plugin for WordPress
CVE-2026-18510

7.2HIGH

What is CVE-2026-18510?

The TranslatePress plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping in comment content. This allows unauthenticated attackers to insert arbitrary web scripts into pages, which will execute when users access the affected pages. Although comment moderation may delay the exploitation for first-time commenters, it does not prevent it entirely, as the payload leverages WordPress-permitted tags combined with percent-encoded characters, evading standard URL validation.

Affected Version(s)

TranslatePress – Translate Multilingual sites with AI Translation 0 <= 3.2.6

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pham Duc Anh
.