Vulnerabilities / GPTranslate / WPSEC-2026-0595

GPTranslate <= 2.34.13 - Unauthenticated Cross-Site Scripting via HTML Attribute Values in Server-Side Translated Pages

Medium 6.1 CWE-79Fixed in 2.34.14
ID
WPSEC-2026-0595
Plugin
GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI (gptranslate)
Affected
all versions before 2.34.14
Remediation
Update to 2.34.14 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness
CWE-79
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
GPTranslate on WPSec AttackSurface
Fix released
Published

Description

The GPTranslate plugin for WordPress is vulnerable to Cross-Site Scripting via HTML attribute values in pages rendered by the server-side translation feature with the DOMDocument or SimpleHTMLDOM engine in all versions up to, and including, 2.34.13. This is due to insufficient output escaping: the translated page is entity-decoded after its attribute values have been escaped. This makes it possible for unauthenticated attackers to inject arbitrary web scripts into translated pages that execute when a user accesses the affected page.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0