CVE-2026-86604: GTranslate < 5.0.1 - Unauthenticated Arbitrary Shortcode Execution via Email Translation

Published Sep 23, 2026
·
Updated

The GTranslate WordPress plugin before 5.0.1 does not remove shortcodes from the content of outgoing emails before expanding them which, in a non-default configuration, allows unauthenticated users to have arbitrary shortcodes registered on the site executed server side.

Affected Software

1 affected component
GTranslate GTranslate WordPress plugin<5.0.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade GTranslate WordPress plugin to a version that resolves this vulnerability.

    Fixed in 5.0.1

Event History

Sep 23, 2026
CVE Published
via MITRE·10:11 AM
Data Sourced
via MITRE·10:11 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which sites are exposed to this issue?

Sites using a GTranslate version earlier than 5.0.1 are affected only when configured to translate outgoing email content. This is a non-default configuration.

2

What does an attacker need to exploit it?

No authentication or user interaction is required, but the attacker must be able to cause content containing a shortcode to be included in an outgoing translated email. Exploitation also depends on relevant shortcodes being registered on the site.

3

What is the practical impact?

An attacker may cause arbitrary shortcodes registered by the site to execute server-side through outgoing email translation. The stated impact includes limited confidentiality and integrity effects, with no availability impact.

4

How can I determine whether immediate mitigation is needed?

Check whether GTranslate is below version 5.0.1 and whether outgoing email translation has been enabled. If both conditions apply, review the site’s registered shortcodes and paths by which unauthenticated users can influence content sent in outgoing emails.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203