๐Ÿ” CVE Alert

CVE-2026-94239

UNKNOWN 0.0

Loco Translate < 2.8.9 - Translator+ Stored XSS via Bundle Configuration

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Loco Translate WordPress plugin before 2.8.9 does not sanitise and escape some bundle configuration values before outputting them back in an admin page, allowing users with the translator capability and above to perform Stored Cross-Site Scripting attacks against high privilege users such as administrators.

Vendor unknown
Product loco translate
Published Oct 3, 2026
Stay Ahead of the Next One

Get instant alerts for unknown loco translate

Be the first to know when new unknown vulnerabilities affecting unknown loco translate are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Loco Translate
0 < 2.8.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/6ab3ec44-cf3b-43ac-8c84-51291e9759dc/

Credits

Het Kalariya WPScan