CVE-2025-15695
GTranslate < 3.0.10 - Admin+ Stored XSS
CVSS Score
3.5
EPSS Score
0.0%
EPSS Percentile
0th
The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScript that runs in the session of any visitor to the site.
| Vendor | unknown |
| Product | translate wordpress with gtranslate |
| Published | Sep 11, 2026 |
| Last Updated | Sep 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown translate wordpress with gtranslate
Be the first to know when new low vulnerabilities affecting unknown translate wordpress with gtranslate are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Translate WordPress with GTranslate
0 < 3.0.10
References
Credits
Dmitrii Ignatyev WPScan