SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2025-15695

LOW · CVSS 3.5 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The Translate WordPress with GTranslate plugin prior to version 3.0.10 is vulnerable due to insufficient validation of settings, enabling users with administrator privileges to inject malicious JavaScript that executes in the session of any site visitor. This could lead to session hijacking or other client-side attacks. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential risks.

CVE
CVE-2025-15695
Severity
LOW
CVSS
3.5
EPSS
0.14%
WordPress Java

Original NVD Description

The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScript that runs in the session of any visitor to the site.