TranslatePress <= 3.3.3 - Unauthenticated Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML Parser
high
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML Parser in all versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unau...
- CVSS:
- 7.2
- Affected:
- up to 3.3.3
- Fixed in:
- 3.3.4
- Disclosed:
- Aug 27, 2026
CVE-2026-76053 on NVD →
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
critical
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it possible for unauthenticated attackers to extract the raw administrator...
- CVSS:
- 9.8
- Affected:
- up to 3.3.1
- Fixed in:
- 3.3.2
- Disclosed:
- Aug 25, 2026
CVE-2026-19632 on NVD →
TranslatePress <= 3.2.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Approved Comment Body in Translation Editor
medium
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Approved Comment Body Rendered in Translation Editor Strings Dropdown in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This m...
- CVSS:
- 6.4
- Affected:
- up to 3.2.6
- Fixed in:
- 3.3
- Disclosed:
- Aug 24, 2026
CVE-2026-18512 on NVD →
TranslatePress – Translate Multilingual sites with AI Translation <= 3.3.2 - Unauthenticated Stored Cross-Site Scripting
high
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.3.2. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrar...
- CVSS:
- 7.2
- Affected:
- up to 3.3.2
- Fixed in:
- 3.3.3
- Disclosed:
- Aug 19, 2026
CVE-2026-66582 on NVD →
TranslatePress – Translate Multilingual sites with AI Translation <= 3.2.5 - Unauthenticated Stored Cross-Site Scripting
high
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to unauthenticated Stored Cross-Site Scripting in versions up to and including 3.2.5. The special gettext markers '#!trpst#' and '#!trpen#' are unconditionally rewritten to '<' and '>' by translate_page() in include...
- CVSS:
- 7.2
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.6
- Disclosed:
- Aug 18, 2026
CVE-2026-75981 on NVD →
TranslatePress <= 3.2.6 - Unauthenticated Stored Cross-Site Scripting via Comment Content
high
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content (URL-encoded gettext markers) in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for una...
- CVSS:
- 7.2
- Affected:
- up to 3.2.6
- Fixed in:
- 3.3
- Disclosed:
- Aug 5, 2026
CVE-2026-18510 on NVD →
TranslatePress <= 3.2.5 - Reflected Cross-Site Scripting
medium
The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in versions up to, and including, 3.2.5. This is due to the translate_page() function unconditionally replacing the plugin's internal #!trpst# and #!trpen# marker tokens with lite...
- CVSS:
- 6.1
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.6
- Disclosed:
- Aug 4, 2026
CVE-2026-17505 on NVD →
TranslatePress <= 2.10.2 - Unauthenticated PHP Object Injection
high
The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.10.2 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable s...
- CVSS:
- 8.1
- Affected:
- up to 2.10.2
- Fixed in:
- 2.10.3
- Disclosed:
- Sep 24, 2025
CVE-2025-58592 on NVD →
TranslatePress <= 2.9.6 - Authenticated (Administrator+) PHP Object Injection
high
The TranslatePress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.9.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulner...
- CVSS:
- 7.2
- Affected:
- up to 2.9.6
- Fixed in:
- 2.9.7
- Disclosed:
- Mar 27, 2025
CVE-2025-30773 on NVD →
Translate Multilingual sites – TranslatePress [translatepress-multilingual] < 2.9.7
unknown
[en] Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress allows Object Injection. This issue affects TranslatePress: from n/a through 2.9.6.
- Affected:
- up to 2.9.7
- Fixed in:
- 2.9.7
- Disclosed:
- Mar 27, 2025
CVE-2025-30773 on NVD →
Translate Multilingual sites – TranslatePress [translatepress-multilingual] < 2.7.6
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs, Razvan Mocanu, Madalin Ungureanu, Cristophor Hurduban TranslatePress.This issue affects TranslatePress: from n/a through 2.7.5.
- Affected:
- up to 2.7.6
- Fixed in:
- 2.7.6
- Disclosed:
- May 10, 2024
CVE-2024-34827 on NVD →
Translate Multilingual sites – TranslatePress <= 2.7.5 - Cross-Site Request Forgery
medium
The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.5. This is due to missing or incorrect nonce validation on the trp_prepare_options_for_database_optimization() function. This makes it possible for unauthenticated...
- CVSS:
- 4.3
- Affected:
- up to 2.7.5
- Fixed in:
- 2.7.6
- Disclosed:
- May 9, 2024
CVE-2024-34827 on NVD →
Translate Multilingual sites – TranslatePress [translatepress-multilingual] < 2.3.3
unknown
[en] The Translate Multilingual sites WordPress plugin before 2.3.3 is vulnerable to an authenticated SQL injection. By adding a new language (via the settings page) containing specific special characters, the backticks in the SQL query can be surpassed and a time-based blind payload can be injected.
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.3
- Disclosed:
- Sep 19, 2022
CVE-2022-3141 on NVD →
TranslatePress <= 2.3.2 - Authenticated (Administrator+) SQL Injection
high
The Translate Multilingual sites WordPress plugin is vulnerable to an authenticated SQL injection in versions up to, and including, 2.3.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. By adding a new language (via the settings page) containing...
- CVSS:
- 7.2
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.3
- Disclosed:
- Jul 23, 2022
CVE-2022-3141 on NVD →
Translate Multilingual sites – TranslatePress [translatepress-multilingual] < 2.0.9
unknown
[en] The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' function only removes script tag with a regex, still allowing other HTML tags and attributes to execute javascript, which could lead to authenticated Stored Cross-Site Scri...
- Affected:
- up to 2.0.9
- Fixed in:
- 2.0.9
- Disclosed:
- Sep 27, 2021
CVE-2021-24610 on NVD →
TranslatePress <= 2.0.8 - Authenticated Stored Cross-Site Scripting
medium
The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' function only removes script tag with a regex, still allowing other HTML tags and attributes to execute javascript, which could lead to authenticated Stored Cross-Site Scripting...
- CVSS:
- 4.8
- Affected:
- up to 2.0.9
- Fixed in:
- 2.0.9
- Disclosed:
- Aug 30, 2021
CVE-2021-24610 on NVD →
Translate Multilingual sites – TranslatePress [translatepress-multilingual] < 2.10.3
unknown
- Affected:
- up to 2.10.3
- Fixed in:
- 2.10.3
CVE-2025-58592 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database