Stored Cross-Site Scripting Vulnerability in TranslatePress Plugin by WordPress
CVE-2026-89412

7.2HIGH

What is CVE-2026-89412?

The TranslatePress plugin for WordPress contains a vulnerability that allows for stored cross-site scripting through the Translation Memory Suggestion Panel. This issue arises from inadequate input sanitization and output escaping in versions up to and including 3.3.5. Unauthenticated attackers can exploit this flaw by injecting malicious web scripts into the translation memory's original column, which are executed when other users access affected pages. The vulnerability exists due to the front-end rendering process, which fails to apply necessary filtering, permitting the execution of harmful payloads stored in the system.

Affected Version(s)

TranslatePress – Translate Multilingual sites with AI Translation 0 <= 3.3.5

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yu Liu
.