๐Ÿ” CVE Alert

CVE-2025-15695

LOW 3.5

GTranslate < 3.0.10 - Admin+ Stored XSS

CVSS Score
3.5
EPSS Score
0.0%
EPSS Percentile
0th

The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScript that runs in the session of any visitor to the site.

Vendor unknown
Product translate wordpress with gtranslate
Published Sep 11, 2026
Last Updated Sep 11, 2026
Stay Ahead of the Next One

Get instant alerts for unknown translate wordpress with gtranslate

Be the first to know when new low vulnerabilities affecting unknown translate wordpress with gtranslate are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Translate WordPress with GTranslate
0 < 3.0.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/423b6be0-e0f2-42c0-8b40-4015e4a0e670/

Credits

Dmitrii Ignatyev WPScan