Sceawere
Vulnerability Detail
CVE-2026-103309UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
GPTranslate Stored XSS Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- GPTranslate
- Attack Type
- CWE-79 Cross-Site Scripting (XSS)
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
The GPTranslate WordPress plugin before 2.34.14 does not properly restrict who can store translations, and does not escape them when outputting them in translated pages, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks when server-side translations are enabled.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-08T06:16:37.287Z",
"pubdate": "2026-10-08T06:16:37.287Z",
"executiveSummary": "The GPTranslate WordPress plugin, specifically versions prior to 2.34.14, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability.\nThe flaw arises due to insufficient access controls regarding who can store translation data combined with a failure to sanitize or escape input before rendering it on the front end.\nThis vulnerability allows unauthenticated remote attackers to inject malicious scripts directly into the application's database if server-side translations are enabled.\nWhen a user or administrator subsequently visits a page where the malicious translation is rendered, the injected script executes within the context of the victim's browser.\nThe impact includes potential session hijacking, unauthorized actions performed on behalf of the user, redirection to malicious websites, or the theft of sensitive session cookies.\nBecause the payload is persistent and server-side, it poses a significant risk to all users viewing the affected content, necessitating immediate remediation.",
"technicalDetails": "The root cause of this vulnerability lies in the improper handling of user-supplied input during the translation storage process. The GPTranslate plugin fails to implement adequate authorization checks, allowing unauthenticated entities to submit translation data. Furthermore, the application fails to perform necessary output encoding or sanitization when this stored data is retrieved from the database and displayed on translated pages.\nThe attack flow begins when an attacker identifies that server-side translations are active. The attacker crafts a payload, typically a JavaScript injection (e.g., <script>alert('XSS')</script>), and submits it to the translation storage endpoint. Since the plugin does not validate the requester's identity or privilege level for these submissions, the server accepts the malicious string and persists it to the WordPress database.\nWhen a legitimate user, such as an administrator or a visitor, loads a web page that utilizes the poisoned translation, the plugin fetches the malicious string from the database and echoes it directly into the HTML source of the page without applying secure output escaping functions such as esc_html() or esc_js().\nThis lack of context-aware output encoding ensures that the victim's browser interprets the injected data as executable code rather than plain text. Consequently, the browser executes the attacker's script in the context of the vulnerable site. This grants the attacker access to the document object model (DOM), enabling them to read sensitive user information, modify page content, or initiate requests to other administrative endpoints if the victim is a privileged user.\nThe vulnerability affects all versions of the GPTranslate plugin prior to 2.34.14. The attack requires no authentication and is accessible over any network where the WordPress instance is exposed. Successful exploitation depends entirely on the server-side translation feature being enabled, which serves as the primary injection vector for the malicious payload."
}