CVE-2025-15695

The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScript that runs in the session of any visitor to the site.

  • Published Sep 11, 2026
  • CVSS 3.5 low
  • 0.1% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2025-15695 at the National Vulnerability Database