Impact
The vulnerability is an improper neutralization of input during web page generation that permits a stored cross‑site scripting flaw in the TranslatePress Multilingual plugin. By inserting crafted content, an attacker can cause arbitrary JavaScript to be executed when site visitors view affected pages. The flaw is classified under CWE‑79.
Affected Systems
WordPress installations that have the TranslatePress plugin from Cozmoslabs, version 3.3.6 or earlier, are susceptible. Any site running a version up to and including 3.3.6 can be impacted, regardless of the site's specific configuration or content structure.
Risk and Exploitability
The issue carries a CVSS score of 7.1, indicating high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this stored XSS by adding malicious content through the plugin’s administrative interfaces, affecting all users who view pages where the injected script appears. No additional privileges are needed beyond normal content editing access.
OpenCVE Enrichment