Description
The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScript that runs in the session of any visitor to the site.
Published: 2026-09-11
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting (XSS)
Action: Patch
AI Analysis

Impact

The Translate WordPress with GTranslate plugin prior to version 3.0.10 fails to validate a configuration setting before generating page markup, allowing administrators to store arbitrary JavaScript that will be delivered to and executed in the browsers of any site visitor. This stored XSS flaw enables malicious code to run within the context of users visiting the site.

Affected Systems

Any WordPress installation that has the Translate WordPress with GTranslate plugin installed and running a version earlier than 3.0.10.

Risk and Exploitability

The vulnerability requires local administrative access to inject malicious code, but the impact is visible to all page visitors. The CVSS score of 3.5 signals a low severity, and the EPSS score of < 1% indicates a very low probability of exploitation. The defect is not listed in the CISA KEV catalog, indicating no known widespread exploitation yet.

Generated by OpenCVE AI on September 11, 2026 at 14:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Translate WordPress with GTranslate plugin to version 3.0.10 or later, which implements proper input validation for the vulnerable setting.
  • Temporarily disable the GTranslate plugin until a patch is available.
  • Limit administrator accounts to only those who truly need administrative privileges and audit role assignments for excess permissions.
  • Configure a Content Security Policy that blocks inline scripts and restricts script sources to trusted origins.

Generated by OpenCVE AI on September 11, 2026 at 14:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Fri, 11 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScript that runs in the session of any visitor to the site.
Title GTranslate < 3.0.10 - Admin+ Stored XSS
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-11T10:11:31.876Z

Reserved: 2026-09-08T08:29:32.811Z

Link: CVE-2025-15695

cve-icon Vulnrichment

Updated: 2026-09-11T10:06:32.481Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T07:16:44.617

Modified: 2026-09-11T17:35:21.440

Link: CVE-2025-15695

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T14:30:19Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')