WordPress Plugin Vulnerabilities

GPTranslate < 2.34.14 - Unauthenticated Stored XSS via REST API Translation Storage

Description

The plugin does not properly restrict who can store translations, and does not escape them when outputting them in translated pages, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks when server-side translations are enabled.

Proof of Concept

Affects Plugins

Fixed in 2.34.14

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Guntur Wahyu Ramadhan
Submitter
Guntur Wahyu Ramadhan
Verified
Yes

Timeline

Publicly Published
2026-10-06 (about 2 days ago)
Added
2026-10-06 (about 1 day ago)
Last Updated
2026-10-07 (about 8 hours ago)

Other