Showing 2 vulnerabilities on this page for TranslatePress – Translate Multilingual sites with AI Translation

Signals CISA KEV Ransomware Nuclei
cozmoslabs vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

TranslatePress <= 3.2.6 - Unauthenticated Stored Cross-Site Scripting via Comment Content

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content (URL-encoded gettext markers) in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Comment moderation may delay exploitation for first-tim

CWE-79Aug 6, 2026
CVSS7.2v3.1EPSS0.243%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

TranslatePress <= 3.2.5 - Reflected Cross-Site Scripting

The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in versions up to, and including, 3.2.5. This is due to the translate_page() function unconditionally replacing the plugin's internal #!trpst# and #!trpen# marker tokens with literal angle brackets across the entire HTML page output after WordPress has already sanitized and escaped user input — allowing the attacker to bypass WordPress's normal HTML escapin

CWE-79Aug 5, 20261 related artifact
CVSS6.1v3.1EPSS0.804%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX