CVE-2026-103062: WordPress TranslatePress plugin <= 3.3.6 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Stored XSS.This issue affects TranslatePress: from n/a through 3.3.6.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress TranslatePress pluginto a version that resolves this vulnerability.Fixed in 3.3.7
Event History
Frequently Asked Questions
Does exploitation require authentication or user interaction?
The CVSS vector indicates no privileges are required and the attack can be conducted over the network with low complexity. However, user interaction is required for exploitation.
What impact is indicated if exploitation succeeds?
The reported impact is low confidentiality, integrity, and availability impact, with scope changed. The vulnerability is classified as stored XSS, meaning injected content may persist and affect subsequent users who encounter it.