{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awordpressthe_transliterator_multilingual_and_multi_script_text_conversion/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:the_transliterator_multilingual_and_multi_script_text_conversion:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-96575"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["The Transliterator – Multilingual and Multi-script Text Conversion (\u003c= 2.5.8)"],"_cs_severities":["high"],"_cs_tags":["xss","wordpress","web-vulnerability"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Transliterator - Multilingual and Multi-script Text Conversion plugin for WordPress (all versions up to and including 2.5.8) contains a stored cross-site scripting (XSS) vulnerability. The flaw arises due to insufficient input sanitization and output escaping when processing comment content. Unauthenticated attackers can exploit this by injecting payloads that leverage the plugin's predictable {rstr_keep} placeholder token. Because the WordPress core 'kses' allow-list permits specific HTML tags and attributes (such as 'a' with the 'title' attribute and 'code' tags), the malicious payloads bypass standard save-time sanitization routines. When a site administrator or visitor views a comment containing the injected script, the payload executes within the victim's browser session. This vulnerability poses a significant risk for session hijacking, unauthorized actions performed on behalf of authenticated users, and defacement of the affected WordPress site.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary web scripts in the browser of any user who views the compromised content. This may lead to the theft of session cookies (enabling account takeover), forced redirection to malicious domains, or unauthorized administrative actions if an authenticated WordPress user views the comment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate The Transliterator plugin to a version released after 2.5.8 immediately.\u003c/li\u003e\n\u003cli\u003eIf a patched version is not available, disable the plugin or restrict comment submission capabilities for unauthenticated users as a temporary mitigation.\u003c/li\u003e\n\u003cli\u003eImplement a strict Content Security Policy (CSP) to mitigate the impact of XSS vulnerabilities by restricting the sources of executable scripts.\u003c/li\u003e\n\u003cli\u003eMonitor server-side web application logs for unusual POST requests directed at comment submission endpoints that contain suspicious HTML attributes or script tokens.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-03T06:54:33Z","date_published":"2026-10-03T06:54:33Z","id":"https://feed.craftedsignal.io/briefs/2026-10-transliterator-xss/","summary":"An unauthenticated stored XSS vulnerability in The Transliterator plugin (\u003c= 2.5.8) allows attackers to inject malicious JavaScript into WordPress comments, leading to arbitrary code execution in the context of site viewers.","title":"Stored Cross-Site Scripting in The Transliterator WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-transliterator-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wordpress:the_transliterator_multilingual_and_multi_script_text_conversion:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}