Junglewise Threat Intelligence

CVE-2026-86604: GTranslate WordPress plugin arbitrary shortcode execution via email translation

CVE-2026-86604 · Severity: medium · CVSS 4.8 · Published 2026-09-23

Executive brief

GTranslate is a WordPress plugin that translates website content for international audiences. A flaw in how it processes outgoing emails allows unauthenticated attackers to execute arbitrary shortcodes on the server in non-default configurations, potentially leading to code execution and site compromise.

Technical details

The plugin fails to sanitize shortcodes from email content before expansion, allowing injection of arbitrary shortcodes. An unauthenticated attacker can exploit this via the email translation feature in non-default configurations to achieve server-side code execution through registered shortcode handlers.

Affected products

  • GTranslate GTranslate before 5.0.1

Timeline

  • 2026-09-23: disclosed
  • 2026-09-23: patched: Fixed in version 5.0.1

References

Related threats