VYPR

TranslatePress

by WordPress

CVEs (9)

  • CVE-2026-78267CriAug 24, 2026
    risk 0.64cvss 9.8epss

    Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.

  • CVE-2025-58592HigNov 6, 2025
    risk 0.53cvss 8.1epss 0.00

    Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Object Injection.This issue affects TranslatePress: from n/a through <= 2.10.2.

  • CVE-2026-75981HigAug 19, 2026
    risk 0.47cvss 7.2epss 0.00

    The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to unauthenticated Stored Cross-Site Scripting in versions up to and including 3.2.5. The special gettext markers '#!trpst#' and '#!trpen#' are unconditionally rewritten to…

  • CVE-2026-18510HigAug 6, 2026
    risk 0.47cvss 7.2epss 0.00

    The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content (URL-encoded gettext markers) in all versions up to, and including, 3.2.6 due to insufficient input sanitization and…

  • CVE-2025-30773HigMar 27, 2025
    risk 0.47cvss 7.2epss 0.01

    Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Object Injection.This issue affects TranslatePress: from n/a through <= 2.9.6.

  • CVE-2026-66582HigAug 20, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions.

  • CVE-2026-17505MedAug 5, 2026
    risk 0.40cvss 6.1epss 0.01

    The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in versions up to, and including, 3.2.5. This is due to the translate_page() function unconditionally replacing the plugin's internal…

  • CVE-2021-24610MedSep 27, 2021
    risk 0.35cvss 4.8epss 0.05

    The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' function only removes script tag with a regex, still allowing other HTML tags and attributes to execute javascript, which could lead to…

  • CVE-2024-34827MedMay 14, 2024
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs, Razvan Mocanu, Madalin Ungureanu, Cristophor Hurduban TranslatePress.This issue affects TranslatePress: from n/a through 2.7.5.