CVE-2025-15695: GTranslate < 3.0.10 - Admin+ Stored XSS
Published Sep 11, 2026
·Updated
The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScript that runs in the session of any visitor to the site.
Affected Software
1 affected component
WordPress with GTranslate WordPress plugin<3.0.10
Event History
Sep 11, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can be impacted if this is exploited?
JavaScript stored through the vulnerable setting can run in the browser session of any visitor to the affected site. This includes visitors who did not interact with the plugin setting themselves.
2
What access does an attacker need to exploit this issue?
The attacker needs access to store a malicious value in the affected plugin setting. The issue is described as exploitable by a user with administrator-level access.