Description
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Translation Memory Suggestion Panel (v-html on suggestion.original) in all versions up to, and including, 3.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Unauthenticated attackers can seed the translation dictionary's original column with executable HTML because the front-end rendering pipeline decodes entity-encoded payloads via html_entity_decode() before persistence, and the original column is deliberately exempt from kses filtering — meaning no save-time sanitizer neutralizes the stored payload before it is later rendered in an administrator's session.
Published: 2026-09-22
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Stored Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

TranslatePress for WordPress is vulnerable to a stored cross‑site scripting flaw when a user seeds the translation memory suggestion panel. The plugin fails to sanitize the "original" column of suggested translations, allowing attackers to embed executable scripts that will later be rendered in the front‑end and in administrator sessions. This can lead to cookie theft, session hijacking, defacement, or the execution of arbitrary malicious code.

Affected Systems

All installations of the TranslatePress plugin by cozmoslabs, version 3.3.5 and earlier, are affected. Versions later than 3.3.5 are not listed as vulnerable.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity potential impact, and although the EPSS score is not available, the vulnerability is not listed in the CISA KEV catalog, suggesting limited exploitation data. The likely attack vector is via the translation memory suggestions interface, where an unauthenticated user can submit payloads that are stored unfiltered and later rendered as part of page content for all site visitors and administrators.

Generated by OpenCVE AI on September 22, 2026 at 08:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the TranslatePress plugin to version 3.3.6 or later, which removes the unsafe v‑html handling.
  • If an immediate upgrade is not possible, disable or restrict the Translation Memory Suggestion Panel to authenticated administrators only and delete any malicious entries from the original column in the database.
  • Apply a Content‑Security‑Policy that disallows execution of inline scripts on the WordPress site to reduce the risk of payload execution while a patch is pending.

Generated by OpenCVE AI on September 22, 2026 at 08:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.3/assets/src/js/components/translation-memory.vue#L12 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.3/includes/class-translation-memory.php#L47 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.3/includes/class-translation-memory.php#L60 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.3/includes/class-translation-render.php#L1024 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.3/includes/class-translation-render.php#L996 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.5/assets/src/js/components/translation-memory.vue#L12 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.5/includes/class-translation-memory.php#L47 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.5/includes/class-translation-memory.php#L60 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.5/includes/class-translation-render.php#L1024 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.5/includes/class-translation-render.php#L996 cve-icon cve-icon
https://plugins.trac.wordpress.org/changeset/3697206/translatepress-multilingual/trunk/assets/src/js/components/translation-memory.vue cve-icon cve-icon
https://plugins.trac.wordpress.org/changeset?reponame=&new=3697206%40translatepress-multilingual%2Ftags%2F3.3.6&old=3686891%40translatepress-multilingual%2Ftags%2F3.3.5 cve-icon cve-icon
https://www.wordfence.com/threat-intel/vulnerabilities/id/717e8479-921b-4f18-8fbe-32e0d8a37590?source=cve cve-icon cve-icon
History

Tue, 22 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Cozmoslabs
Cozmoslabs translatepress – Translate Multilingual Sites With Ai Translation
Wordpress
Wordpress wordpress
Vendors & Products Cozmoslabs
Cozmoslabs translatepress – Translate Multilingual Sites With Ai Translation
Wordpress
Wordpress wordpress

Tue, 22 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Translation Memory Suggestion Panel (v-html on suggestion.original) in all versions up to, and including, 3.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Unauthenticated attackers can seed the translation dictionary's original column with executable HTML because the front-end rendering pipeline decodes entity-encoded payloads via html_entity_decode() before persistence, and the original column is deliberately exempt from kses filtering — meaning no save-time sanitizer neutralizes the stored payload before it is later rendered in an administrator's session.
Title TranslatePress <= 3.3.5 - Unauthenticated Stored Cross-Site Scripting via Translation Memory Suggestion Panel
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Cozmoslabs Translatepress – Translate Multilingual Sites With Ai Translation
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-22T06:39:40.880Z

Reserved: 2026-09-11T16:38:29.057Z

Link: CVE-2026-89412

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-22T07:16:29.927

Modified: 2026-09-22T07:16:29.927

Link: CVE-2026-89412

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T08:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')