Impact
The Translate WordPress with GTranslate plugin prior to version 3.0.10 fails to validate a configuration setting before generating page markup, allowing administrators to store arbitrary JavaScript that will be delivered to and executed in the browsers of any site visitor. This stored XSS flaw enables malicious code to run within the context of users visiting the site.
Affected Systems
Any WordPress installation that has the Translate WordPress with GTranslate plugin installed and running a version earlier than 3.0.10.
Risk and Exploitability
The vulnerability requires local administrative access to inject malicious code, but the impact is visible to all page visitors. The CVSS score of 3.5 signals a low severity, and the EPSS score of < 1% indicates a very low probability of exploitation. The defect is not listed in the CISA KEV catalog, indicating no known widespread exploitation yet.
OpenCVE Enrichment