DIRAS TAKE
Urgent: this is a pre-auth stored XSS that requires no login, so attackers can seed persistent payloads remotely; mitigate exposure immediately and prioritize protective controls for admin and suggestion interfaces.
What is CVE-2026-89412?
Unauthenticated attackers can store and later execute arbitrary JavaScript in sites using the TranslatePress – Translate Multilingual sites with AI Translation plugin, tracked as CVE-2026-89412. The flaw affects branch 3.x, versions 3.3.5 and earlier, and arises from improper sanitization and output escaping in the Translation Memory Suggestion Panel where original text can include executable HTML. An attacker only needs network access to a site that accepts translation suggestions to inject payloads that will run when a victim loads an affected page or an administrator views the suggestion. The weakness is classified as CWE-79 (Cross-site Scripting).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Which versions of cozmoslabs TranslatePress – Translate Multilingual sites with AI Translation are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 3.x | 3.3.5 and earlier |
Is CVE-2026-89412 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-89412
- If possible, disable or remove the TranslatePress plugin until the vendor issues a fix.
- Restrict access to the translation suggestion interface and administrative pages to trusted networks or IPs.
- Monitor web and application logs for unexpected submission activity and signs of stored script execution.
- Follow and apply any vendor guidance or updates as soon as a patched release is published.
Frequently asked questions
Is CVE-2026-89412 being actively exploited?
There are no public reports of exploitation of CVE-2026-89412 as of 2026-09-30.
Which TranslatePress versions are affected by CVE-2026-89412?
TranslatePress branch 3.x, specifically versions 3.3.5 and earlier, are identified as affected.
Is there a patch for CVE-2026-89412?
No fixed versions are listed in the available facts; await a vendor release or apply the provided mitigations.
Does CVE-2026-89412 require authentication?
No, the vulnerability allows unauthenticated attackers to store malicious scripts in the suggestion data.
References
- nvd.nist.gov/vuln/detail/CVE-2026-89412
- cve.org/CVERecord?id=CVE-2026-89412
- wordfence.com/threat-intel/vulnerabilities/id/717e8479-921b-4f18-8fbe-32e0d8a37590?source=cve
- plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.5/assets/src/js/components/translation-memory.vue#L12
- plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.5/includes/class-translation-memory.php#L47
- plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.5/includes/class-translation-memory.php#L60
- plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.5/includes/class-translation-render.php#L1024
- plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.5/includes/class-translation-render.php#L996
- plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.3/assets/src/js/components/translation-memory.vue#L12
- plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.3/includes/class-translation-memory.php#L47
- plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.3/includes/class-translation-memory.php#L60
- plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.3/includes/class-translation-render.php#L1024
- plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.3/includes/class-translation-render.php#L996
- plugins.trac.wordpress.org/changeset?reponame=&new=3697206%40translatepress-multilingual%2Ftags%2F3.3.6&old=3686891%40translatepress-multilingual%2Ftags%2F3.3.5
- plugins.trac.wordpress.org/changeset/3697206/translatepress-multilingual/trunk/assets/src/js/components/translation-memory.vue
- All cozmoslabs CVEs on CVE Radar
- CVEs published in September 2026