HIGH
ivijanstefan
CVE published 2026-10-03
CVE-2026-96575
The Transliterator – Multilingual and Multi-script Text Conversion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content due to insufficient input sanitization and output escaping. This allows unauthenticated attackers to inject web scripts that execute when a user accesses an injected page. The vulnerability exists in all versions up to, and including, 2.5.8 of the Transli [truncated]