Impact
The TranslatePress plugin for WordPress, versions 3.2.5 and earlier, contains a reflected cross‑site scripting flaw. The flaw arises when the plugin’s translate_page() function performs an indiscriminate replacement of internal marker tokens with literal angle brackets in the output of every HTML page after WordPress has already performed its normal sanitisation. Attackers can exploit this by inserting the marker tokens within the value of the ‘s’ search parameter in a URL. When an unsuspecting user follows the crafted link, the browser interprets the injected script tag and executes arbitrary JavaScript in the context of the site, enabling session theft, cookie theft, phishing, or other client‑side attacks. This vulnerability is accessible to unauthenticated users and requires only a malicious link; no login or elevated privileges are required.
Affected Systems
The vulnerability affects the TranslatePress Multilingual plugin, a product supplied by cozmoslabs and designed for multilingual WordPress sites. All versions up to and including 3.2.5 are impacted.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity vulnerability, but the potential for widespread damage is limited to individuals who click the malicious link, usually via social engineering or compromised posts. EPSS data is currently unavailable, and the vulnerability is not included in the CISA KEV catalog, implying that it is not yet a widely exploited or tracked threat. Nonetheless, because the flaw is remote, unauthenticated, and deeply integrated with site pages, it poses a significant risk to any site running affected versions of TranslatePress. Implementing the vendor-supplied fix should be treated as a high‑priority mitigation.
OpenCVE Enrichment