{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/translate-multilingual-sites-with-ai-translation-3.3.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-76053"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Translate Multilingual sites with AI Translation (3.3.3)"],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","xss","wordpress"],"_cs_type":"advisory","_cs_vendors":["TranslatePress"],"content_html":"\u003cp\u003eTranslatePress versions 3.3.3 and below for WordPress contain a stored Cross-Site Scripting (XSS) vulnerability (CVE-2026-76053). The flaw arises from insufficient input sanitization and output escaping within the plugin's translation parser. An unauthenticated attacker can exploit WordPress comment KSES allowlist configurations by injecting a crafted combination of anchor tags (href and title attributes) and code tags. This payload bypasses standard filters and is stored directly in the WordPress database. When the plugin processes these comments for page translation, the injected scripts are rendered and executed in the browser of any user viewing the page. This vulnerability poses a significant risk to site administrators and users, as it can be used for session hijacking, credential theft, or unauthorized actions performed on behalf of the victim.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of the victim's session. This can lead to full site compromise if administrative sessions are targeted, unauthorized modifications to site content, or the theft of sensitive user data from affected pages.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the TranslatePress plugin to version 3.3.4 or higher immediately to remediate the sanitization deficiency. Ensure that standard WordPress commenting permissions are restricted to authenticated users where possible to reduce the attack surface for unauthenticated exploitation. If updating is not immediately feasible, disable the plugin's translation feature for public comment sections.\u003c/p\u003e\n","date_modified":"2026-08-28T07:12:01Z","date_published":"2026-08-28T07:12:01Z","id":"https://feed.craftedsignal.io/briefs/2026-08-translatepress-xss/","summary":"The TranslatePress plugin for WordPress is vulnerable to unauthenticated stored XSS through improper sanitization of comment data, allowing attackers to inject persistent malicious scripts.","title":"Stored Cross-Site Scripting in TranslatePress WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-translatepress-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Translate Multilingual Sites With AI Translation (3.3.3)","version":"https://jsonfeed.org/version/1.1"}