PT-2026-104534 · WordPress · Loco Translate
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Loco Translate WordPress plugin versions prior to 2.8.9
Description
Insufficient sanitization and escaping of bundle configuration values before they are output on an admin page allows users with translator capabilities or higher to execute Stored Cross-Site Scripting (XSS) attacks against high-privilege users, such as administrators. Stored Cross-Site Scripting is a type of attack where malicious scripts are permanently stored on the target server.
Recommendations
Update the plugin to version 2.8.9 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Loco Translate