CVE-2025-15695

The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScript that runs in the session of any visitor to the site.

Scoring

Severity
LOW
CVSS base score
3.5
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
EPSS probability
0.14%
Published
2026-09-11
Last modified
2026-09-11

Affected products

Markdown version · Browse all CVEs