<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Translate Multilingual Sites With AI Translation (3.3.3) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/translate-multilingual-sites-with-ai-translation-3.3.3/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 28 Aug 2026 07:12:01 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/translate-multilingual-sites-with-ai-translation-3.3.3/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored Cross-Site Scripting in TranslatePress WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-08-translatepress-xss/</link><pubDate>Fri, 28 Aug 2026 07:12:01 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-translatepress-xss/</guid><description>The TranslatePress plugin for WordPress is vulnerable to unauthenticated stored XSS through improper sanitization of comment data, allowing attackers to inject persistent malicious scripts.</description><content:encoded><![CDATA[<p>TranslatePress versions 3.3.3 and below for WordPress contain a stored Cross-Site Scripting (XSS) vulnerability (CVE-2026-76053). The flaw arises from insufficient input sanitization and output escaping within the plugin's translation parser. An unauthenticated attacker can exploit WordPress comment KSES allowlist configurations by injecting a crafted combination of anchor tags (href and title attributes) and code tags. This payload bypasses standard filters and is stored directly in the WordPress database. When the plugin processes these comments for page translation, the injected scripts are rendered and executed in the browser of any user viewing the page. This vulnerability poses a significant risk to site administrators and users, as it can be used for session hijacking, credential theft, or unauthorized actions performed on behalf of the victim.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of the victim's session. This can lead to full site compromise if administrative sessions are targeted, unauthorized modifications to site content, or the theft of sensitive user data from affected pages.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update the TranslatePress plugin to version 3.3.4 or higher immediately to remediate the sanitization deficiency. Ensure that standard WordPress commenting permissions are restricted to authenticated users where possible to reduce the attack surface for unauthenticated exploitation. If updating is not immediately feasible, disable the plugin's translation feature for public comment sections.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application-vulnerability</category><category>xss</category><category>wordpress</category></item></channel></rss>