CVE-2026-66582
- EPSS -
- Veröffentlicht 20.08.2026 12:16:32
- Zuletzt bearbeitet 20.08.2026 17:19:24
Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions.
CVE-2026-75981
- EPSS 0.25%
- Veröffentlicht 19.08.2026 06:37:55
- Zuletzt bearbeitet 20.08.2026 12:48:10
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to unauthenticated Stored Cross-Site Scripting in versions up to and including 3.2.5. The special gettext markers '#!trpst#' and '#!trpen#' are u...
CVE-2026-18510
- EPSS 0.24%
- Veröffentlicht 06.08.2026 05:29:25
- Zuletzt bearbeitet 12.08.2026 21:00:52
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content (URL-encoded gettext markers) in all versions up to, and including, 3.2.6 due to insufficient ...
CVE-2026-17505
- EPSS 0.8%
- Veröffentlicht 05.08.2026 06:37:57
- Zuletzt bearbeitet 12.08.2026 21:00:37
The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in versions up to, and including, 3.2.5. This is due to the translate_page() function unconditionally replaci...
CVE-2025-58592
- EPSS 0.37%
- Veröffentlicht 06.11.2025 15:54:20
- Zuletzt bearbeitet 15.04.2026 00:35:42
Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Object Injection.This issue affects TranslatePress: from n/a through <= 2.10.2.
CVE-2025-30773
- EPSS 0.75%
- Veröffentlicht 27.03.2025 10:54:40
- Zuletzt bearbeitet 23.04.2026 15:27:02
Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Object Injection.This issue affects TranslatePress: from n/a through <= 2.9.6.
CVE-2024-34827
- EPSS 0.25%
- Veröffentlicht 14.05.2024 15:39:36
- Zuletzt bearbeitet 28.04.2026 19:25:31
Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs, Razvan Mocanu, Madalin Ungureanu, Cristophor Hurduban TranslatePress.This issue affects TranslatePress: from n/a through 2.7.5.
CVE-2022-3141
- EPSS 4.08%
- Veröffentlicht 19.09.2022 14:15:11
- Zuletzt bearbeitet 21.11.2024 07:18:54
The Translate Multilingual sites WordPress plugin before 2.3.3 is vulnerable to an authenticated SQL injection. By adding a new language (via the settings page) containing specific special characters, the backticks in the SQL query can be surpassed a...
CVE-2021-24610
- EPSS 5.43%
- Veröffentlicht 27.09.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 05:53:24
The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' function only removes script tag with a regex, still allowing other HTML tags and attributes to execute jav...