Stored Cross-Site Scripting Vulnerability in TranslatePress Plugin by WordPress
CVE-2026-89412
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 September 2026
What is CVE-2026-89412?
The TranslatePress plugin for WordPress contains a vulnerability that allows for stored cross-site scripting through the Translation Memory Suggestion Panel. This issue arises from inadequate input sanitization and output escaping in versions up to and including 3.3.5. Unauthenticated attackers can exploit this flaw by injecting malicious web scripts into the translation memory's original column, which are executed when other users access affected pages. The vulnerability exists due to the front-end rendering process, which fails to apply necessary filtering, permitting the execution of harmful payloads stored in the system.
Affected Version(s)
TranslatePress β Translate Multilingual sites with AI Translation 0 <= 3.3.5