CVE-2025-15695
EUVD-2025-21088811.09.2026, 07:16
The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScript that runs in the session of any visitor to the site.
Awaiting analysis
This vulnerability is currently awaiting analysis.