cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches fortranslatepress-multilingual translatepress-multilingual

Direction: ascending
Jun 07, 2024

Translate Multilingual sites – TranslatePress # CVE-2024-34827

CVE, Research URL

CVE-2024-34827

Date
May 14, 2024
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs, Razvan Mocanu, Madalin Ungureanu, Cristophor Hurduban TranslatePress.This issue affects TranslatePress: from n/a through 2.7.5.
Affected versions
max 2.7.6.
Status
vulnerable

Translate Multilingual sites – TranslatePress # CVE-2021-24610

CVE, Research URL

CVE-2021-24610

Date
Sep 27, 2021
Research Description
The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' function only removes script tag with a regex, still allowing other HTML tags and attributes to execute javascript, which could lead to authenticated Stored Cross-Site Scripting issues.
Affected versions
max 2.0.9.
Status
vulnerable

Translate Multilingual sites – TranslatePress # CVE-2022-3141

CVE, Research URL

CVE-2022-3141

Date
Sep 19, 2022
Research Description
The Translate Multilingual sites WordPress plugin before 2.3.3 is vulnerable to an authenticated SQL injection. By adding a new language (via the settings page) containing specific special characters, the backticks in the SQL query can be surpassed and a time-based blind payload can be injected.
Affected versions
max 2.3.3.
Status
vulnerable
Mar 28, 2025

Translate Multilingual sites – TranslatePress # CVE-2025-30773

CVE, Research URL

CVE-2025-30773

Date
Mar 27, 2025
Research Description
Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Object Injection.This issue affects TranslatePress: from n/a through <= 2.9.6.
Affected versions
max 2.9.7.
Status
vulnerable
Nov 10, 2025

Translate Multilingual sites &#8211; TranslatePress # CVE-2025-58592

CVE, Research URL

CVE-2025-58592

Date
Nov 06, 2025
Research Description
Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Object Injection.This issue affects TranslatePress: from n/a through <= 2.10.2.
Affected versions
max 2.10.3.
Status
vulnerable
Jul 28, 2026

Translate Multilingual sites &#8211; TranslatePress # PSC-2026-64679

PSC, Research URL

PSC-2026-64679

Date
Jul 28, 2026
Research Description
Multilingual plugins store translated text and insert it into front-end output across themes and other plugins. Visual editing, language routing, and automatic translation features require firm access controls and consistent escaping. TranslatePress - Translate Multilingual sites with AI Translation version 3.2.6 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64679, confirming that the plugin was reviewed from a secure code perspective with attention to translation storage, visual editor permissions, multilingual routing, automatic translation settings, and public output.
Affected versions
Min 3.2.6, max 3.2.6.
Status
SAFE & CERTIFIED
Aug 05, 2026

Translate Multilingual sites &#8211; TranslatePress # CVE-2026-17505

CVE, Research URL

CVE-2026-17505

Date
-
Research Description
TranslatePress &#8211; Translate Multilingual sites with AI Translation [translatepress-multilingual] < 3.2.6 CVE-2026-17505
Affected versions
max 3.2.6.
Status
vulnerable
Aug 07, 2026

Translate Multilingual sites &#8211; TranslatePress # CVE-2026-18510

CVE, Research URL

CVE-2026-18510

Date
Aug 06, 2026
Research Description
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content (URL-encoded gettext markers) in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Comment moderation may delay exploitation for first-time commenters, but does not prevent it, as the payload uses only WordPress-permitted tags and attributes with percent-encoded characters that pass wp_kses URL validation unmodified.
Affected versions
max 3.3.
Status
vulnerable