{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/translatepress--translate-multilingual-sites-with-ai-translation--3.2.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-18510"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["TranslatePress – Translate Multilingual sites with AI Translation (\u003c= 3.2.6)"],"_cs_severities":["high"],"_cs_tags":["xss","wordpress","plugin-vulnerability"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe TranslatePress - Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) in versions up to and including 3.2.6. The vulnerability stems from inadequate input sanitization and output escaping when processing URL-encoded gettext markers within comment content.\u003c/p\u003e\n\u003cp\u003eBecause the malicious payload utilizes percent-encoded characters, it successfully circumvents the WordPress \u003ccode\u003ewp_kses\u003c/code\u003e filtering mechanism, which typically validates tags and attributes. While WordPress's comment moderation feature may introduce a minor delay for unauthenticated users, it does not prevent the persistent injection of the script. Once successfully injected into a comment, the script executes within the context of any user who views the compromised page. This poses a significant risk for administrative account compromise or session hijacking, as the script triggers automatically upon page load.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of victims viewing affected pages. This can lead to session hijacking, unauthorized actions performed on behalf of authenticated users, or the redirection of visitors to malicious sites. The vulnerability affects all sites running TranslatePress versions 3.2.6 and earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the TranslatePress plugin to the latest available version beyond 3.2.6.\u003c/li\u003e\n\u003cli\u003eIf updating is not possible, disable the comment feature or utilize a Web Application Firewall (WAF) to block requests containing anomalous URL-encoded patterns commonly associated with XSS payloads targeting gettext markers.\u003c/li\u003e\n\u003cli\u003eDeploy webserver logging to monitor for anomalous POST requests containing encoded script tags in comment submission parameters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-06T09:22:26Z","date_published":"2026-08-06T09:22:26Z","id":"https://feed.craftedsignal.io/briefs/2026-08-translatepress-xss/","summary":"The TranslatePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to insufficient input sanitization of URL-encoded gettext markers, allowing unauthenticated attackers to inject persistent malicious scripts.","title":"Stored XSS in TranslatePress Plugin via URL-Encoded Gettext Markers","url":"https://feed.craftedsignal.io/briefs/2026-08-translatepress-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - TranslatePress – Translate Multilingual Sites With AI Translation (\u003c= 3.2.6)","version":"https://jsonfeed.org/version/1.1"}