LOW
GTranslate
CVE published 2026-09-11
CVE-2025-15695
The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScript that runs in the session of any visitor to the site. This vulnerability allows administrators to store JavaScript that can run in visitor sessions, potentially leading [truncated]