CVE-2025-15695
The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScript that runs in the session of any visitor to the site.
- Published Sep 11, 2026
- CVSS 3.5 low
- 0.1% chance of exploitation in the next 30 days (EPSS)
- A fix is available