Get real-time updates on Telegram
Verified
CVE-2026-103309: GPTranslate 0 to before 2.34.14
Affected technology
GPTranslate · 0 to before 2.34.14
Vendor not specified by the source
Description’s affected range: before 2.34.14 does not properly restrict who can store translations
Component: Not specified by the source
What an attacker can do
The source says the GPTranslate WordPress plugin before 2.34.14 does not properly restrict who can store translations, and does not escape them when outputting them in translated pages, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks when server-side translations are enabled.
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-08 08:50:52.119177+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 08:49:39.219831+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-103309.html