Unauthenticated Stored Cross-Site Scripting in TranslatePress Plugin for WordPress
CVE-2026-75981

7.2HIGH

What is CVE-2026-75981?

The TranslatePress plugin for WordPress is susceptible to an unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in versions up to and including 3.2.5. This occurs due to improper handling of special gettext markers, which can be injected by an attacker into comments. When these markers are processed, they render as HTML elements, allowing attackers to execute scripts in the context of a user's browser. The vulnerability arises from the insufficient sanitization of input, which fails to strip out harmful tags other than and . Users of affected versions should consider upgrading or applying necessary patches to mitigate this risk.

Affected Version(s)

TranslatePress – Translate Multilingual sites with AI Translation 0 <= 3.2.5

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pham Duc Anh
.