Executive brief
TranslatePress is a WordPress plugin that enables websites to be translated into multiple languages. Attackers can inject malicious code into website comments that will execute in the browsers of visitors viewing those pages, potentially compromising visitor accounts or stealing sensitive data. This vulnerability requires no special access and affects all installations using the plugin.
Technical details
The vulnerability is a Stored Cross-Site Scripting (XSS) flaw in the TranslatePress plugin's comment processing and HTML parsing logic. The root cause is insufficient input sanitization and output escaping in the plugin's HTML parser (simple_html_dom.php), combined with WordPress's default comment KSES allowlist that permits anchor tags with href/title attributes and code tags. Attackers can craft malicious comments that bypass WordPress's comment sanitization filters; these payloads are stored verbatim in the database and later executed when the page is accessed and translated. The vulnerability is network-accessible and unauthenticated, requiring only the ability to post a comment. An attacker can achieve arbitrary JavaScript execution in the context of any user viewing the affected page, enabling session hijacking, credential theft, or defacement. Patches are available in versions after 3.3.3.
Affected products
- TranslatePress TranslatePress – Translate Multilingual sites with AI Translation up to and including 3.3.3
Timeline
- 2026-08-28: disclosed: Vulnerability disclosed and CVE-2026-76053 published