Skip to main content

CVE-2025-8719: WordPress gTranslate Plugin XSS Vulnerability

CVE-2025-8719 is a stored XSS vulnerability in the Translate This gTranslate Shortcode plugin for WordPress affecting versions up to 1.0. Attackers with contributor access can inject malicious scripts via the base_lang parameter. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2025-8719 Overview

CVE-2025-8719 is a Stored Cross-Site Scripting (XSS) vulnerability in the Translate This gTranslate Shortcode plugin for WordPress. The flaw affects all versions up to and including 1.0. The base_lang parameter fails to sanitize input and escape output before rendering. Authenticated users with Contributor-level access or higher can inject arbitrary JavaScript into pages. The payload executes in the browser of any visitor who loads the affected page. The vulnerability is tracked under CWE-79 and carries a CVSS 3.1 score of 6.4.

Critical Impact

Authenticated contributors can persist JavaScript payloads that execute in the context of site visitors, enabling session theft, credential harvesting, and privilege escalation against higher-privileged users.

Affected Products

  • Translate This gTranslate Shortcode plugin for WordPress
  • All versions up to and including 1.0
  • WordPress sites permitting Contributor-level or higher registration

Discovery Timeline

  • 2025-08-16 - CVE-2025-8719 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-8719

Vulnerability Analysis

The plugin exposes a shortcode that accepts a base_lang parameter used to configure the Google Translate web element. The plugin renders the supplied value directly into page markup. Without sanitization or contextual output escaping, an authenticated user can embed HTML and JavaScript through the shortcode attribute. When any visitor loads the page containing the shortcode, the injected script runs in the visitor's browser under the site's origin.

Stored XSS in a WordPress plugin is particularly useful to attackers because payloads persist in the database and target any user who views the affected content. In WordPress deployments, contributors can create draft content; once an editor or administrator previews or publishes it, their authenticated session becomes exposed to the attacker's script.

Root Cause

The root cause is missing input validation on the base_lang shortcode attribute combined with the absence of output escaping when the attribute is written back to the HTML response. WordPress provides functions such as sanitize_text_field(), esc_attr(), and esc_html() for these purposes, but the vulnerable code path does not apply them before rendering the attribute value.

Attack Vector

A network-based attacker with Contributor-level credentials creates or edits a post containing the plugin shortcode with a malicious base_lang value. The payload is stored in the WordPress database. When a higher-privileged user or unauthenticated visitor renders the post, the browser executes the injected JavaScript. Attackers can pivot to session theft, forced administrative actions via authenticated fetch calls, or drive-by redirects to external malware.

No verified public proof-of-concept is available. For technical detail on the vulnerable code path, review the WordPress Plugin Source and the Wordfence Vulnerability Analysis.

Detection Methods for CVE-2025-8719

Indicators of Compromise

  • Post or page content in wp_posts containing the plugin shortcode with <script>, onerror=, onload=, or javascript: sequences inside the base_lang attribute.
  • Unexpected outbound requests from visitor browsers to attacker-controlled domains after loading pages that use the translation shortcode.
  • New Contributor or Author accounts created shortly before injection of shortcode content.

Detection Strategies

  • Query the WordPress database for shortcode instances of the plugin and inspect the base_lang value against an allowlist of expected language codes (for example, en, es, fr).
  • Deploy a web application firewall rule that inspects POST bodies to /wp-admin/post.php and /wp-admin/admin-ajax.php for shortcode attributes containing HTML tags or event handlers.
  • Enable Content Security Policy (CSP) reporting to identify inline script execution originating from post content.

Monitoring Recommendations

  • Alert on privilege changes and role assignments touching Contributor, Author, Editor, or Administrator roles.
  • Monitor plugin activation logs and file changes under wp-content/plugins/translate-this-google-translate-web-element-shortcode/.
  • Review WordPress access logs for anomalous authenticated edits followed by rapid public views of the same post ID.

How to Mitigate CVE-2025-8719

Immediate Actions Required

  • Deactivate and remove the Translate This gTranslate Shortcode plugin until a patched version is confirmed available.
  • Audit existing posts and pages for shortcode invocations and remove or sanitize any suspicious base_lang values.
  • Restrict Contributor and Author account creation, and review recently created low-privilege accounts.

Patch Information

At the time of NVD publication, no fixed version had been identified beyond 1.0. Consult the Wordfence advisory and the plugin developer page for updates. Apply any vendor-released patch as soon as it is published.

Workarounds

  • Remove the plugin from production sites and replace it with a maintained translation solution.
  • Enforce a strict Content Security Policy that disallows inline script execution in rendered post content.
  • Require multi-factor authentication for all authenticated WordPress roles to raise the cost of Contributor account compromise.
  • Use a web application firewall to block shortcode attributes containing HTML tags or JavaScript event handlers.
bash
# Example: locate vulnerable shortcode instances in the WordPress database
wp db query "SELECT ID, post_title FROM wp_posts \
  WHERE post_content REGEXP 'base_lang=\"[^\"]*(<|javascript:|on[a-z]+=)'"

# Example: disable the plugin from the CLI
wp plugin deactivate translate-this-google-translate-web-element-shortcode
wp plugin delete translate-this-google-translate-web-element-shortcode

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.