PT-2026-68016 · WordPress · Translatepress
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
TranslatePress versions prior to 3.2.6
Description
Reflected Cross-Site Scripting occurs when the
translate page() function unconditionally replaces internal marker tokens #!trpst# and #!trpen# with literal angle brackets in the HTML page output. This process happens after WordPress has sanitized and escaped user input, allowing unauthenticated attackers to bypass standard HTML escaping by including these tokens in the s parameter of a search query. This enables the injection of arbitrary web scripts that execute when a user clicks a specially crafted link.Recommendations
Update to a version newer than 3.2.5.
Avoid using the
s parameter in search queries until the update is applied.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Translatepress