Cozmoslabs

Translatepress

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 20.08.2026 12:16:32
  • Zuletzt bearbeitet 20.08.2026 17:19:24

Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions.

  • EPSS 0.25%
  • Veröffentlicht 19.08.2026 06:37:55
  • Zuletzt bearbeitet 20.08.2026 12:48:10

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to unauthenticated Stored Cross-Site Scripting in versions up to and including 3.2.5. The special gettext markers '#!trpst#' and '#!trpen#' are u...

  • EPSS 0.24%
  • Veröffentlicht 06.08.2026 05:29:25
  • Zuletzt bearbeitet 12.08.2026 21:00:52

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content (URL-encoded gettext markers) in all versions up to, and including, 3.2.6 due to insufficient ...

  • EPSS 0.8%
  • Veröffentlicht 05.08.2026 06:37:57
  • Zuletzt bearbeitet 12.08.2026 21:00:37

The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in versions up to, and including, 3.2.5. This is due to the translate_page() function unconditionally replaci...

  • EPSS 0.37%
  • Veröffentlicht 06.11.2025 15:54:20
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Object Injection.This issue affects TranslatePress: from n/a through <= 2.10.2.

  • EPSS 0.75%
  • Veröffentlicht 27.03.2025 10:54:40
  • Zuletzt bearbeitet 23.04.2026 15:27:02

Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Object Injection.This issue affects TranslatePress: from n/a through <= 2.9.6.

  • EPSS 0.25%
  • Veröffentlicht 14.05.2024 15:39:36
  • Zuletzt bearbeitet 28.04.2026 19:25:31

Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs, Razvan Mocanu, Madalin Ungureanu, Cristophor Hurduban TranslatePress.This issue affects TranslatePress: from n/a through 2.7.5.

Exploit
  • EPSS 4.08%
  • Veröffentlicht 19.09.2022 14:15:11
  • Zuletzt bearbeitet 21.11.2024 07:18:54

The Translate Multilingual sites WordPress plugin before 2.3.3 is vulnerable to an authenticated SQL injection. By adding a new language (via the settings page) containing specific special characters, the backticks in the SQL query can be surpassed a...

Exploit
  • EPSS 5.43%
  • Veröffentlicht 27.09.2021 16:15:08
  • Zuletzt bearbeitet 21.11.2024 05:53:24

The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' function only removes script tag with a regex, still allowing other HTML tags and attributes to execute jav...