Stored Cross-Site Scripting in TranslatePress Multilingual Plugin for WordPress
CVE-2026-18512
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 August 2026
What is CVE-2026-18512?
The TranslatePress plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input validation and output escapement in the Approved Comment Body section of the Translation Editor Strings dropdown. This flaw allows authenticated users, starting from subscriber-level roles, to inject malicious web scripts that can execute on any page a user accesses. Consequently, it poses a significant risk of data manipulation and unauthorized access to sensitive information for users interacting with affected pages.
Affected Version(s)
TranslatePress β Translate Multilingual sites with AI Translation 0 <= 3.2.6