Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Yu Liu

#41709of 57,356
7.2Total CVSS
Vulnerabilities · 1
PT-2026-96650
7.2
2026-09-22
WordPress · Translatepress · CVE-2026-89412
**Name of the Vulnerable Software and Affected Versions** TranslatePress versions prior to 3.3.6 **Description** Insufficient input sanitization and output escaping in the Translation Memory Suggestion Panel allow unauthenticated attackers to perform Stored Cross-Site Scripting (XSS). Attackers can inject arbitrary web scripts into the translation dictionary's original column because the front-end rendering pipeline uses `html entity decode()` on entity-encoded payloads before persistence, and the original column is exempt from kses filtering (a process used to sanitize HTML). These scripts execute when a user, such as an administrator, accesses the affected page. The issue specifically involves the `v-html` directive on the `suggestion.original` variable. **Recommendations** Update to a version newer than 3.3.5.