{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/translatepress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-75981"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["TranslatePress – Translate Multilingual sites with AI Translation"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["TranslatePress"],"content_html":"\u003cp\u003eThe TranslatePress plugin for WordPress (versions 3.2.5 and below) contains a critical security flaw that enables unauthenticated stored cross-site scripting (XSS). The vulnerability exists within the 'translate_page' function in 'includes/class-translation-render.php', which performs an unconditional replacement of the custom gettext markers '#!trpst#' and '#!trpen#' with the HTML brackets '\u0026lt;' and '\u0026gt;'. Because these markers are treated as plain text by standard WordPress sanitization filters like 'wp_kses', they pass through unchanged into the database. When a visitor views a post or comment in a language targeted by the plugin, the rendering engine replaces the markers with HTML tags, allowing an attacker to inject arbitrary HTML, including event handlers like 'onerror'. Because the plugin's 'remove_tags_from_output' function only targets '\u0026lt;script\u0026gt;' and '\u0026lt;style\u0026gt;' tags, attackers can successfully execute JavaScript using alternative tags such as '\u0026lt;img\u0026gt;'. This vulnerability poses a significant risk to site visitors, potentially leading to session theft or administrative account compromise if a privileged user views the injected content.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress site utilizing the vulnerable TranslatePress plugin (version \u0026lt;= 3.2.5).\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious payload using the plugin's specific markers, such as '#!trpst#img src=x onerror=alert(1)#!trpen#'.\u003c/li\u003e\n\u003cli\u003eAttacker submits the payload via a vector that accepts user-supplied content, such as a post comment or a custom form field.\u003c/li\u003e\n\u003cli\u003eThe WordPress site stores the payload in the database because 'wp_kses' does not recognize the markers as HTML.\u003c/li\u003e\n\u003cli\u003eThe attacker waits for an unsuspecting victim or site administrator to load the page with the TranslatePress plugin enabled.\u003c/li\u003e\n\u003cli\u003eThe TranslatePress 'translate_page()' function processes the stored comment and substitutes the markers with real HTML brackets.\u003c/li\u003e\n\u003cli\u003eThe browser renders the resulting \u0026lt;img\u0026gt; tag, and the 'onerror' event handler executes the malicious JavaScript payload in the victim's session.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the execution of arbitrary JavaScript in the context of the victim's browser session. This can lead to the theft of session cookies, redirection of users to malicious domains, or unauthorized actions performed on behalf of the logged-in user. Given that WordPress sites often attract administrative users to comment threads or post editing interfaces, the risk of credential or session hijacking is high.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the TranslatePress plugin to the latest version, which contains the patch for this vulnerability.\u003c/li\u003e\n\u003cli\u003eAudit existing comments and posts on the site for the presence of the '#!trpst#' or '#!trpen#' substrings as an indicator of potential past exploitation.\u003c/li\u003e\n\u003cli\u003eImplement a strong Content Security Policy (CSP) to restrict the execution of unauthorized scripts and mitigate the impact of potential XSS vulnerabilities.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-19T10:14:30Z","date_published":"2026-08-19T10:14:30Z","id":"https://feed.craftedsignal.io/briefs/2026-08-translatepress-xss/","summary":"The TranslatePress plugin for WordPress is vulnerable to unauthenticated stored cross-site scripting due to improper handling of translation markers, allowing attackers to inject malicious HTML into post content.","title":"Unauthenticated Stored XSS in TranslatePress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-translatepress-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - TranslatePress","version":"https://jsonfeed.org/version/1.1"}