{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-89412/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:translatepress:translatepress:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-89412"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["TranslatePress (\u003c= 3.3.5)"],"_cs_severities":["high"],"_cs_tags":["web-application","xss","wordpress","cve-2026-89412"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe TranslatePress - Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) in all versions up to and including 3.3.5. The vulnerability stems from improper input sanitization and output escaping within the Translation Memory Suggestion Panel. Specifically, the plugin uses \u003ccode\u003ehtml_entity_decode()\u003c/code\u003e on input payloads before persistence into the database, and the relevant column is explicitly exempt from \u003ccode\u003ekses\u003c/code\u003e filtering. This allows unauthenticated attackers to inject malicious HTML and JavaScript into the translation dictionary. When an administrator later views the affected translation page, the payload is rendered via \u003ccode\u003ev-html\u003c/code\u003e and executed within their browser session. This flaw could lead to unauthorized administrative actions, session hijacking, or site-wide impact if the script performs further malicious operations.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of an administrator session. This can lead to full site compromise, unauthorized configuration changes, or the exfiltration of sensitive data, affecting any WordPress installation running the vulnerable TranslatePress version.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the update of the TranslatePress plugin to the latest version. Monitor web server access logs for anomalous POST requests directed at endpoints responsible for saving translation memory data. Review the site's WordPress installation for unauthorized modifications to translation dictionary tables. Ensure that Content Security Policy (CSP) headers are implemented to mitigate the impact of potential XSS attacks.\u003c/p\u003e\n","date_modified":"2026-09-22T08:34:12Z","date_published":"2026-09-22T08:34:12Z","id":"https://feed.craftedsignal.io/briefs/2026-09-translatepress-xss/","summary":"The TranslatePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the Translation Memory Suggestion Panel, allowing unauthenticated attackers to execute arbitrary scripts in administrator sessions.","title":"Stored Cross-Site Scripting in TranslatePress WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-translatepress-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-89412","version":"https://jsonfeed.org/version/1.1"}