๐Ÿ” CVE Alert

CVE-2026-94238

UNKNOWN 0.0

Loco Translate < 2.8.9 - Translator+ Limited File Read via 'path' Parameter

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Loco Translate WordPress plugin before 2.8.9 does not restrict which file paths its translation file routes will read, allowing users granted the Loco Translate WordPress plugin before 2.8.9's translator capability to retrieve the contents of files of certain types from anywhere on the server, including outside the web root.

Vendor unknown
Product loco translate
Published Oct 3, 2026
Stay Ahead of the Next One

Get instant alerts for unknown loco translate

Be the first to know when new unknown vulnerabilities affecting unknown loco translate are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Loco Translate
0 < 2.8.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/76d339bf-094c-459d-9f6c-caeda5e97892/

Credits

Shivamani Vastrala WPScan