Search Results (1 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-103309 1 Wordpress-extensions 1 Gptranslate 2026-10-09 7.5 High
The GPTranslate WordPress plugin before 2.34.14 does not properly restrict who can store translations, and does not escape them when outputting them in translated pages, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks when server-side translations are enabled.