Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

CVE-2026-9109 is a high-severity stored cross-site scripting vulnerability in the GPTranslate WordPress plugin, affecting all versions up to and including 2.31. The flaw combines two weaknesses: an API key derived directly from the site URL and exposed in page source, and unsanitized input on the translation storage endpoint, allowing any unauthenticated visitor to inject persistent malicious scripts into affected pages. Any WordPress site running this plugin is at risk of session hijacking, credential theft, or malicious redirects affecting all visitors until the plugin is updated or disabled.

Author

Tech Jacks Solutions