Impact
The vulnerability in TranslatePress allows an attacker to store malicious script payloads in comment content by using URL‑encoded gettext markers that bypass WordPress’s wp_kses sanitization. Once a comment is accepted, the injected code executes in the browsers of any user who views the affected page, giving the attacker the ability to steal session cookies, deface content, or execute arbitrary client‑side actions.
Affected Systems
WordPress sites that have installed TranslatePress versions up to and including 3.2.6. The vulnerability is present in all editions of the plugin bundled with the TranslatePress – Translate Multilingual sites with AI Translation plugin, irrespective of the WordPress theme or other plugins used.
Risk and Exploitability
The vulnerability scores a CVSS of 7.2, indicating a high confidence of significant impact. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw through unauthenticated comment submission, meaning any visitor can potentially inject payloads, though editor approval may delay activation on first‑time comments. Once the comment is published, the stored XSS is executed automatically for all users who view the page.
OpenCVE Enrichment