{"error":0,"message":null,"data":{"name":"Loco Translate","plugin":"loco-translate","link":"https:\/\/wordpress.org\/plugins\/loco-translate\/","latest":"1785594060","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"e34c9a2acec2d1fd5c9597d5b84d5b74fb7e533218a59dce1c6a09c1c0e0afa1","name":"Loco Translate [loco-translate] < 2.5.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.5.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24721","name":"CVE-2021-24721","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24721","description":"[en] The Loco Translate WordPress plugin before 2.5.4 mishandles data inputs which get saved to a file, which can be renamed to an extension ending in .php, resulting in authenticated \"translator\" users being able to inject PHP code into files ending with .php in web accessible locations.","date":"2021-11-08"},{"id":"2531948ab62ed7254fa3a43f2009f2891ec42558","name":"WordPress Loco Translate plugin <= 2.5.3 - Authenticated PHP Code Injection vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/loco-translate\/vulnerability\/wordpress-loco-translate-plugin-2-5-3-authenticated-php-code-injection-vulnerability","description":"Authenticated PHP Code Injection vulnerability discovered by Tomi Ashari in WordPress Loco Translate plugin (versions <= 2.5.3).","date":"2021-10-11"},{"id":"22ca0d6bb7d6776483c8f4b5321618d16b0228a1","name":"Loco Translate <= 2.5.3 - Authenticated PHP Code Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/loco-translate\/loco-translate-253-authenticated-php-code-injection","description":"The Loco Translate WordPress plugin before 2.5.4 mishandles data inputs which get saved to a file, which can be renamed to an extension ending in .php, resulting in authenticated \"translator\" users being able to inject PHP code into files ending with .php in web accessible locations.","date":"2021-10-11"},{"id":"bc7d4774-fce8-4b0b-8015-8ef4c5b02d38","name":"Loco Translate &lt; 2.5.4 - Authenticated PHP Code Injection","link":"https:\/\/wpscan.com\/vulnerability\/bc7d4774-fce8-4b0b-8015-8ef4c5b02d38","description":"The plugin mishandles data inputs which get saved to a file, which can be renamed to an extension ending in .php, resulting in authenticated &quot;translator&quot; users being able to inject PHP code into files ending with .php in web accessible locations.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:H\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"h","a":"n","score":"6.5","severity":"m","exploitable":"2.8","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:H\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"high","a":"none","exploitable":"2.8","impact":"3.6"},"cwe":[{"cwe":"CWE-94","name":"Improper Control of Generation of Code ('Code Injection')","description":"The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment."}]}},{"uuid":"754daebc5cc2a1d6cc9c538742fe6fbb38374da5c582f26f47fc85a91dc13e2b","name":"Loco Translate [loco-translate] < 2.6.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.6.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-0765","name":"CVE-2022-0765","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-0765","description":"[en] The Loco Translate WordPress plugin before 2.6.1 does not properly remove inline events from elements in the source translation strings before outputting them in the editor in the plugin admin panel, allowing any user with access to the plugin (Translator and Administrator by default) to add arbitrary javascript payloads to the source strings leading to a stored cross-site scripting (XSS) vulnerability.","date":"2022-04-18"},{"id":"2696f9df73f269ae0310b8c4867a384b60b778ef","name":"WordPress Loco Translate plugin <= 2.6.0 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/loco-translate\/vulnerability\/wordpress-loco-translate-plugin-2-6-0-authenticated-stored-cross-site-scripting-xss-vulnerability","description":"Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Taurus Omar in WordPress Loco Translate plugin (versions <= 2.6.0).","date":"2022-03-22"},{"id":"ba2cc97a765b02f40767ffa39696b3c569a1f6a7","name":"Loco Translate <= 2.6.0 - Authenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/loco-translate\/loco-translate-260-authenticated-stored-cross-site-scripting","description":"The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via elements in versions up to, and including, 2.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the plugin, such as translators and site administrators, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2022-03-22"},{"id":"58838f51-323d-41e0-8c85-8e113dc2c587","name":"Loco Translate &lt; 2.6.1 - Authenticated Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/58838f51-323d-41e0-8c85-8e113dc2c587","description":"The plugin does not properly remove inline events from elements in the source translation strings before outputting them in the editor in the plugin admin panel, allowing any user with access to the plugin (Translator and Administrator by default) to add arbitrary javascript payloads to the source strings leading to a stored cross-site scripting (XSS) vulnerability.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"cda821d9235726e19ef35c46ac6dec17de2afc99316bbe5c9c4f1780c0880bf6","name":"Loco Translate [loco-translate] < 2.2.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"eb96c8c0-2b0d-43c0-a89e-8b8363962a6d","name":"Loco Translate &lt; 2.2.2 - Authenticated LFI","link":"https:\/\/wpscan.com\/vulnerability\/eb96c8c0-2b0d-43c0-a89e-8b8363962a6d","description":"WordPress plugin Loco Translate version appears to have an Authenticated LFI Vulnerability under the &#039;Edit Template&#039; Functionality. \r\n\r\nThe following vulnerability can be exploited by any user with access to the plugin (access can range from Admin to Subscriber)\r\n\r\nWPScanTeam Note: Was not able to reproduce this issue with any user other than admin.","date":null}],"impact":[]},{"uuid":"c35ab8c66e7879afa6193710bbf63f3461a92df1ebb865bf24def8588d231bac","name":"Loco Translate [loco-translate] < 2.6.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.6.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-37236","name":"CVE-2024-37236","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-37236","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in Tim W Loco Translate loco-translate allows Cross Site Request Forgery.This issue affects Loco Translate: from n\/a through <= 2.6.9.","date":"2025-01-02"},{"id":"606eea18a25994042dc1a79381d85ab12354eeee","name":"WordPress Loco Translate Plugin <= 2.6.9 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/loco-translate\/vulnerability\/wordpress-loco-translate-plugin-2-6-9-cross-site-request-forgery-csrf-vulnerability","description":"<p>WordPress Loco Translate Plugin <= 2.6.9 is vulnerable to Cross Site Request Forgery (CSRF)<\/p><p>Software: Loco Translate<\/p><p>Link: https:\/\/wordpress.org\/plugins\/loco-translate\/#developers<\/p><p>Affected Version <= 2.6.9<\/p><p>Fixed in version 2.6.10 <\/p>","date":"2024-06-21"},{"id":"a6fa2a6fa1ddc4b301efdb2b991f972cbf76a297","name":"Loco Translate <= 2.6.9 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/loco-translate\/loco-translate-269-cross-site-request-forgery","description":"The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.9. This is due to missing or incorrect nonce validation on the 'init' function. This makes it possible for unauthenticated attackers to save or delete a configuration via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2024-06-21"},{"id":"EUVD-2024-37053","name":"EUVD-2024-37053","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-37053","description":"Cross-Site Request Forgery (CSRF) vulnerability in Tim Whitlock Loco Translate allows Cross Site Request Forgery.This issue affects Loco Translate: from n\/a through 2.6.9.","date":"2025-01-02"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"28bd7778b9a17ae6fe96e831cb8d1d30dee29a2b88031d155e798fc082492c0a","name":"Loco Translate [loco-translate] < 2.8.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-4146","name":"Loco Translate <= 2.8.2 - Reflected Cross-Site Scripting via 'update_href' Parameter","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-4146","description":"The Loco Translate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the \u2018update_href\u2019 parameter in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"0000-00-00"},{"id":"4123c773fbcadd0678daa8c7f228fe8ddf16f250","name":"Loco Translate <= 2.8.2 - Reflected Cross-Site Scripting via 'update_href' Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/loco-translate\/loco-translate-282-reflected-cross-site-scripting-via-update-href-parameter","description":"The Loco Translate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the \u2018update_href\u2019 parameter in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2026-03-30"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"7935fe217da60e2b66b0c9ca5dd6733e4bf9d9387b0994c1664a70c5b7132864","name":"Loco Translate [loco-translate] < 2.8.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-1921","name":"CVE-2026-1921","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-1921","description":"[en] The Loco Translate plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.8.2 via the `fsReference` AJAX route. This is due to the `findSourceFile()` method normalizing user-supplied `ref` paths containing `..\/` directory traversal sequences without validating that the resolved path remains within the intended bundle or content directory. This makes it possible for authenticated attackers, with Translator-level access and above (custom `loco_admin` capability required, granted to the `translator` role and administrators by default), to read arbitrary `.php`, `.js`, `.json`, and `.twig` files from the server filesystem outside the intended translation directory. Files named wp-config.php are excluded.","date":"2026-05-05"},{"id":"47a9c55553e32104d7c723b9036033ef23f4bb01","name":"Loco Translate <= 2.8.2 - Authenticated (Translator+) Path Traversal to Limited File Read via 'ref' Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/loco-translate\/loco-translate-282-authenticated-translator-path-traversal-to-limited-file-read-via-ref-parameter","description":"The Loco Translate plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.8.2 via the `fsReference` AJAX route. This is due to the `findSourceFile()` method normalizing user-supplied `ref` paths containing `..\/` directory traversal sequences without validating that the resolved path remains within the intended bundle or content directory. This makes it possible for authenticated attackers, with Translator-level access and above (custom `loco_admin` capability required, granted to the `translator` role and administrators by default), to read arbitrary `.php`, `.js`, `.json`, and `.twig` files from the server filesystem outside the intended translation directory. Files named wp-config.php are excluded.","date":"2026-05-04"},{"id":"5b135bb8e7ddd44c7024e9c95d5081833807f340","name":"WordPress Loco Translate Plugin <= 2.8.2 is vulnerable to Directory Traversal","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/loco-translate\/vulnerability\/wordpress-loco-translate-plugin-2-8-2-authenticated-translator-path-traversal-to-limited-file-read-vulnerability","description":"<p>WordPress Loco Translate Plugin <= 2.8.2 is vulnerable to Directory Traversal<\/p><p>Software: Loco Translate<\/p><p>Fixed in version 2.8.3 <\/p><p>Affected Version <= 2.8.2<\/p><p>CVE: CVE-2026-1921<\/p>","date":"2026-05-04"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"4.9","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"4.9","severity":"medium","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"0fd5ffebb0ea44c61a655f1b2965e3516399a493b81cc58d5aee73ce5dc95e9f","name":"Loco Translate [loco-translate] < 2.8.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-15005","name":"CVE-2026-15005","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-15005","description":"[en] The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing or incorrect nonce validation on the execTemplate function. This makes it possible for unauthenticated attackers to execute arbitrary PHP code on the server by supplying a php:\/\/filter stream wrapper URI as the 'template' parameter, which bypasses path validation and is passed directly to the include sink in execTemplate() via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2026-07-16"},{"id":"41c926e140c20353da03e9cd920c712c8a080892","name":"Loco Translate <= 2.8.5 - Cross-Site Request Forgery to Remote Code Execution via 'template' Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/loco-translate\/loco-translate-285-cross-site-request-forgery-to-remote-code-execution-via-template-parameter","description":"The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing or incorrect nonce validation on the execTemplate function. This makes it possible for unauthenticated attackers to execute arbitrary PHP code on the server by supplying a php:\/\/filter stream wrapper URI as the 'template' parameter, which bypasses path validation and is passed directly to the include sink in execTemplate() via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2026-07-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"628df735da8e243b001c843c8d00edd2bd7cd2bc76ddbeaf26cef76ee6e83b50","name":"Loco Translate [loco-translate] < 2.8.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-15066","name":"CVE-2026-15066","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-15066","description":"[en] The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in all versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with translator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-08-16"},{"id":"1121277c1214e388a6504d7ba8cc38181e8ca9ac","name":"Loco Translate <= 2.8.7 - Authenticated (Translator+) Stored Cross-Site Scripting via PO File Extracted Comments","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/loco-translate\/loco-translate-287-authenticated-translator-stored-cross-site-scripting-via-po-file-extracted-comments","description":"The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in all versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with translator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-08-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1786947986"}