CVE-2026-103309: GPTranslate < 2.34.14 - Unauthenticated Stored XSS via REST API Translation Storage
The GPTranslate WordPress plugin before 2.34.14 does not properly restrict who can store translations, and does not escape them when outputting them in translated pages, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks when server-side translations are enabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GPTranslateto a version that resolves this vulnerability.Fixed in 2.34.14
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
GPTranslate installations running versions before 2.34.14 are exposed when server-side translations are enabled. The issue affects the plugin's REST API translation storage and translated-page output.
Does an attacker need an account or other privileges?
No. The vulnerability allows unauthenticated users to store translations through the REST API, although exploitation also requires user interaction according to the CVSS vector.
What is the practical impact of successful exploitation?
An attacker can store malicious script content that is later rendered in translated pages. This can lead to stored cross-site scripting with potential impact to confidentiality, integrity, and availability.