Skip to content

Known CVE

WordPress TranslatePress < 3.2.6 - Cross-Site Scripting

TranslatePress plugin < 3.2.6 for WordPress contains a reflected cross-site scripting vulnerability in the translation marker processing feature, letting attackers inject and execute arbitrary JavaScript code, exploit requires no authentication or privileges.

CVE-2026-17505

Medium2026CVSS 6.1CWE-79

cve2026 · wordpress · wp-plugin · wp · translatepress · xss

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website