CVE-2026-89412: stored cross-site scripting in cozmoslabs TranslatePress – Translate Multilingual sites with AI Translation

Unauthenticated attackers can store and later execute arbitrary JavaScript in sites using the TranslatePress – Translate Multilingual sites with AI Translation plugin, tracked as CVE-2026-89412. The flaw affects branch 3.x, versions 3.3.5 and earlier, and arises from improper sanitization and output escaping in the Translation Memory Suggestion Panel where original text can include executable HTML. An attacker only needs network access to a site that accepts translation suggestions to inject payloads that will run when a victim loads an affected page or an administrator views the suggestion.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.2HIGH
EPSS
0.00527
CWE
CWE-79
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: this is a pre-auth stored XSS that requires no login, so attackers can seed persistent payloads remotely; mitigate exposure immediately and prioritize protective controls for admin and suggestion interfaces.

What is CVE-2026-89412?

Unauthenticated attackers can store and later execute arbitrary JavaScript in sites using the TranslatePress – Translate Multilingual sites with AI Translation plugin, tracked as CVE-2026-89412. The flaw affects branch 3.x, versions 3.3.5 and earlier, and arises from improper sanitization and output escaping in the Translation Memory Suggestion Panel where original text can include executable HTML. An attacker only needs network access to a site that accepts translation suggestions to inject payloads that will run when a victim loads an affected page or an administrator views the suggestion. The weakness is classified as CWE-79 (Cross-site Scripting).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Which versions of cozmoslabs TranslatePress – Translate Multilingual sites with AI Translation are affected?

BRANCHAFFECTEDFIXED
3.x3.3.5 and earlier

Is CVE-2026-89412 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-89412

  1. If possible, disable or remove the TranslatePress plugin until the vendor issues a fix.
  2. Restrict access to the translation suggestion interface and administrative pages to trusted networks or IPs.
  3. Monitor web and application logs for unexpected submission activity and signs of stored script execution.
  4. Follow and apply any vendor guidance or updates as soon as a patched release is published.

Frequently asked questions

Is CVE-2026-89412 being actively exploited?

There are no public reports of exploitation of CVE-2026-89412 as of 2026-09-30.

Which TranslatePress versions are affected by CVE-2026-89412?

TranslatePress branch 3.x, specifically versions 3.3.5 and earlier, are identified as affected.

Is there a patch for CVE-2026-89412?

No fixed versions are listed in the available facts; await a vendor release or apply the provided mitigations.

Does CVE-2026-89412 require authentication?

No, the vulnerability allows unauthenticated attackers to store malicious scripts in the suggestion data.

References