Known CVE
WordPress TranslatePress < 3.2.6 - Cross-Site Scripting
TranslatePress plugin < 3.2.6 for WordPress contains a reflected cross-site scripting vulnerability in the translation marker processing feature, letting attackers inject and execute arbitrary JavaScript code, exploit requires no authentication or privileges.
CVE-2026-17505
Medium2026CVSS 6.1CWE-79
cve2026 · wordpress · wp-plugin · wp · translatepress · xss
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website