Impact
TranslatePress for WordPress is vulnerable to a stored cross‑site scripting flaw when a user seeds the translation memory suggestion panel. The plugin fails to sanitize the "original" column of suggested translations, allowing attackers to embed executable scripts that will later be rendered in the front‑end and in administrator sessions. This can lead to cookie theft, session hijacking, defacement, or the execution of arbitrary malicious code.
Affected Systems
All installations of the TranslatePress plugin by cozmoslabs, version 3.3.5 and earlier, are affected. Versions later than 3.3.5 are not listed as vulnerable.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity potential impact, and although the EPSS score is not available, the vulnerability is not listed in the CISA KEV catalog, suggesting limited exploitation data. The likely attack vector is via the translation memory suggestions interface, where an unauthenticated user can submit payloads that are stored unfiltered and later rendered as part of page content for all site visitors and administrators.
OpenCVE Enrichment