Description
The WP Multilang – Translation and Multilingual Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post content in all versions up to, and including, 2.4.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-09-24
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

The WP Multilang plugin possesses a stored XSS flaw in every release up to 2.4.31. Improper sanitization of post content allows an attacker with Contributor‑level access to embed malicious scripts, which are rendered whenever any user views the affected page. The injected scripts run in the victim’s browser and can hijack sessions, deface content, or exfiltrate data, thereby harming the site’s confidentiality, integrity, and user experience.

Affected Systems

The vulnerability affects the WP Multilang – Translation and Multilingual Plugin released by magazine3, specifically all versions up to and including 2.4.31. Any WordPress site running these releases is susceptible.

Risk and Exploitability

The CVSS score of 6.4 indicates moderate severity, and no EPSS value is available to gauge current exploitation likelihood. The flaw does not appear in the CISA KEV list. Attackers must first obtain authenticated Contributor or higher privileges to inject the payload, after which the malicious code executes in the browsers of all visitors to the edited post. Existing edits that contain untrusted input are ideal targets for exploitation.

Generated by OpenCVE AI on September 24, 2026 at 10:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WP Multilang plugin to version 2.4.32 or later to eliminate the stored XSS fix.
  • If an upgrade cannot be performed immediately, disable or delete the plugin until the patch is applied, and then cleanse or re‑create any post content that may contain injected scripts.
  • Restrict or revoke Contributor‑level permissions for users who do not require edit rights, reducing the window of opportunity for malicious script injection.

Generated by OpenCVE AI on September 24, 2026 at 10:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Description The WP Multilang – Translation and Multilingual Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post content in all versions up to, and including, 2.4.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title WP Multilang – Translation and Multilingual Plugin <= 2.4.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Content
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-24T12:32:12.419Z

Reserved: 2026-07-14T13:36:56.403Z

Link: CVE-2026-15731

cve-icon Vulnrichment

Updated: 2026-09-24T12:32:08.972Z

cve-icon NVD

Status : Deferred

Published: 2026-09-24T10:17:36.433

Modified: 2026-09-24T14:40:36.103

Link: CVE-2026-15731

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T10:30:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')