Description
The Transliterator – Multilingual and Multi-script Text Conversion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Predictable {rstr_keep} Placeholder in all versions up to, and including, 2.5.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload survives WordPress comment save-time sanitization because the tags and attributes used (such as a[title] and code) are permitted by the core comment kses allow-list, and the literal characters comprising the plugin's shortcode markers and placeholder tokens are not stripped.
Published: 2026-10-03
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting via unauthenticated comment injection triggering script execution
Action: Immediate Patch
AI Analysis

Impact

XSS flaw in the Transliterator plugin allows unauthenticated users to inject scripts into comment content using the predictable {rstr_keep} placeholder. The plugin does not properly sanitize these tokens and relies on WordPress’ permissive kses filter, letting tags such as <a> and <code> survive. As a result, malicious scripts persist in the database and execute whenever a user views the page, enabling arbitrary JavaScript execution, cookie theft, and potential remote code execution via the user’s browser.

Affected Systems

All versions of the Transliterator – Multilingual and Multi‑script Text Conversion plugin for WordPress up to and including 2.5.8 are affected. The vendor is ivijanstefan.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.2, but no EPSS score is published, and it is not listed in CISA’s KEV catalog. The flaw can be exploited by any user who can post a comment on a WordPress site running a vulnerable plugin version; the attack vector is entirely web‑based and does not require authentication. Once injected, the malicious payload runs in the context of any visitor to the affected page, giving attackers the ability to deface content, steal session cookies, or perform further attacks on the victim’s browser.

Generated by OpenCVE AI on October 3, 2026 at 06:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Transliterator plugin to a version greater than 2.5.8 to eliminate the XSS vector.
  • If an immediate update is not possible, block or disable comments on the site to prevent the insertion of malicious payloads.
  • As a temporary containment measure, implement a Content Security Policy that restricts script execution to trusted domains and blocks inline scripts.

Generated by OpenCVE AI on October 3, 2026 at 06:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description The Transliterator – Multilingual and Multi-script Text Conversion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Predictable {rstr_keep} Placeholder in all versions up to, and including, 2.5.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload survives WordPress comment save-time sanitization because the tags and attributes used (such as a[title] and code) are permitted by the core comment kses allow-list, and the literal characters comprising the plugin's shortcode markers and placeholder tokens are not stripped.
Title Transliterator <= 2.5.8 - Unauthenticated Stored Cross-Site Scripting via Comment Content via Predictable {rstr_keep} Placeholder
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:43.548Z

Reserved: 2026-09-23T13:30:14.837Z

Link: CVE-2026-96575

cve-icon Vulnrichment

Updated: 2026-10-03T15:39:07.447Z

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:47.920

Modified: 2026-10-03T16:16:47.407

Link: CVE-2026-96575

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T06:30:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')