Executive brief
GTranslate is a WordPress plugin that adds translation capabilities and language-switching widgets to websites. An administrator with access to the plugin's settings can inject malicious JavaScript that executes in the browser of every website visitor, including other administrators, potentially leading to account compromise or data theft.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in the GTranslate WordPress plugin before version 3.0.10. The plugin fails to validate the "default_language" setting before using it in front-end markup generation. An authenticated administrator can bypass the plugin's select control by intercepting the settings form submission and injecting a malicious payload (e.g., 123" onmouseover=alert(1)//) into the default_language parameter. When any site visitor views a page containing the plugin's language switcher (via shortcode, widget, or floating selector), the stored payload executes in their session. The vulnerability requires administrator-level privileges to inject the payload but affects all site visitors, including other administrators. The fix was released in version 3.0.10.
Affected products
- GTranslate GTranslate before 3.0.10
Timeline
- 2026-09-09: disclosed
- 2026-09-10: patched: Fixed in version 3.0.10