Stored Cross-Site Scripting Vulnerability in GPTranslate Plugin for WordPress
CVE-2026-9109
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 June 2026
What is CVE-2026-9109?
The GPTranslate plugin for WordPress suffers from a Stored Cross-Site Scripting vulnerability due to insufficient input sanitization and output escaping when handling requests to the REST API Translation Storage. Attackers can exploit this weakness to inject arbitrary web scripts, which will execute when a user accesses an impacted page. Additionally, the API key can be easily accessed from the HTML source, enabling unauthenticated users to submit malicious translation requests, further compromising the security of the site.
Affected Version(s)
GPTranslate β Multilingual AI Translation for WordPress: Automatically Translate Websites 0 <= 2.31