WordPress · Translatepress · CVE-2026-89412
**Name of the Vulnerable Software and Affected Versions**
TranslatePress versions prior to 3.3.6
**Description**
Insufficient input sanitization and output escaping in the Translation Memory Suggestion Panel allow unauthenticated attackers to perform Stored Cross-Site Scripting (XSS). Attackers can inject arbitrary web scripts into the translation dictionary's original column because the front-end rendering pipeline uses `html entity decode()` on entity-encoded payloads before persistence, and the original column is exempt from kses filtering (a process used to sanitize HTML). These scripts execute when a user, such as an administrator, accesses the affected page. The issue specifically involves the `v-html` directive on the `suggestion.original` variable.
**Recommendations**
Update to a version newer than 3.3.5.