Stored Cross-Site Scripting in TranslatePress Plugin for WordPress
CVE-2026-76053

7.2HIGH

What is CVE-2026-76053?

The TranslatePress plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability due to inadequate input validation and output encoding. This issue arises from the mishandling of comment data, allowing unauthorized users to insert harmful scripts. Attackers can exploit this flaw by injecting malicious comments that bypass the filtering process, which are subsequently stored in the database. When users visit affected pages, these scripts execute in their browsers, potentially leading to data theft or site defacement.

Affected Version(s)

TranslatePress – Translate Multilingual sites with AI Translation 0 <= 3.3.3

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daroo
.