What is CVE-2026-18510?
This vulnerability affects the TranslatePress plugin for WordPress up to version 3.2.6, allowing Stored Cross-Site Scripting via URL-encoded gettext markers in comment content. The issue stems from insufficient input sanitization and output escaping. Users should immediately update the plugin to the latest patched version.
Azərbaycanca: Bu zəiflik WordPress üçün TranslatePress plagininin 3.2.6 və daha əvvəlki versiyalarını təsirləyir. Şərh məzmununda URL-kodlanmış gettext markerləri vasitəsilə Stored XSS hücumuna imkan yaradır. İstifadəçilər plaginini ən son versiyaya yeniləməli və şərh bölməsində təhlükəsizlik tədbirlərini artırmalıdır.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the TranslatePress plugin are affected by CVE-2026-18510?
This vulnerability affects the TranslatePress plugin for WordPress up to and including version 3.2.6.
How can users protect themselves from CVE-2026-18510?
Users should immediately update the TranslatePress plugin to the latest patched version and enhance security measures in the comments section.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.