CVE-2026-75981 carries a CVSS 3.1 base score of 7.2 against TranslatePress, a WordPress multilingual translation plugin. NVD classifies it as CWE-79 (Cross-Site Scripting) and states the flaw affects versions up to and including 3.2.5. VulnCheck’s KEV feed reports the CVE as exploited, dated September 10, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-75981 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
NVD’s description states TranslatePress uses internal plain-text placeholder markers during its translation-rendering process, which the plugin’s translate_page() function unconditionally converts into literal HTML angle-bracket characters. NVD states that because these placeholder markers contain no HTML-special characters themselves, they pass through WordPress’s standard comment-sanitization filter (wp_kses) undetected, and an unauthenticated attacker can embed the markers in a public comment so that when TranslatePress later renders the page in a secondary language, the markers are converted into a real, attacker-controlled HTML element. NVD states the plugin’s own output-cleanup step only strips <script> and <style> tags, leaving other elements — including ones capable of executing JavaScript via an event-handler attribute — untouched.
We are deliberately not reproducing the specific placeholder marker strings or the exact comment payload NVD’s description identifies, since doing so would function as a directly usable exploitation instruction rather than vulnerability reporting; readers needing that detail for authorized testing or patch verification should consult the linked vendor source and Wordfence’s threat intelligence entry.
Evidence and confidence
- Medium confidence — the CVSS 7.2 score, the vector (
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N), the CWE-79 classification, the affected version boundary (3.2.5), and the described mechanism all trace to NVD alone in our current ingestion, corroborated by Wordfence’s threat intelligence entry for this CVE. The exploitation report traces to VulnCheck KEV alone. - Low-to-moderate exploitation probability — FIRST’s EPSS model scores this CVE at 0.00245, a 15.9th percentile score as of our ingestion.
No field is in conflict between our two sources.
Why this matters
This is a case where a security control existed but had a gap in its coverage: WordPress’s standard comment sanitization runs and passes the malicious input because the placeholder markers themselves aren’t HTML, and the plugin’s own output-cleanup step only checks for two specific tag types rather than filtering broadly for dangerous elements or attributes. That pattern — sanitization that checks for the wrong thing at the wrong stage of a multi-step rendering pipeline — is a recurring failure mode worth watching for in other plugins that similarly rewrite placeholder text into HTML during rendering. Because this is a stored, unauthenticated XSS reachable through public comments, any site running a pre-3.2.6 version of this plugin with comments enabled should treat this as a priority patch.
Frequently Asked Questions
What is CVE-2026-75981? A CVSS 7.2 stored cross-site scripting vulnerability (CWE-79) in the TranslatePress WordPress plugin, versions up to and including 3.2.5, allowing an unauthenticated attacker to inject malicious content via a public comment that gets converted into executable HTML during the plugin’s translation-rendering process.
Is CVE-2026-75981 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 10, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.
Do I need an account to exploit this? No. NVD’s description confirms this is exploitable by an unauthenticated attacker via a public comment submission.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Is a fixed version available? Our source data does not carry a specific fixed-version number beyond NVD’s statement that versions “up to and including” 3.2.5 are affected. Consult the plugin vendor directly for the current patched release.
Severity, vector, weakness classification, and the described mechanism sourced from the National Vulnerability Database record for CVE-2026-75981, corroborated by Wordfence’s threat intelligence entry. Exploitation status and the September 10, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.