medium · CVSS v3 6.8 · EPSS 0.00157
CVE-2026-94238
The Loco Translate WordPress plugin (v<2.8.9) allows privileged users to read arbitrary files on the server via unrestricted translation fil
Overview
The Loco Translate WordPress plugin (v<2.8.9) allows privileged users to read arbitrary files on the server via unrestricted translation file routes. This flaw can expose sensitive configuration and code files outside the web root. It affects sites running the vulnerable plugin version.
Description
The Loco Translate WordPress plugin before 2.8.9 does not restrict which file paths its translation file routes will read, allowing users granted the Loco Translate WordPress plugin before 2.8.9's translator capability to retrieve the contents of files of certain types from anywhere on the server, including outside the web root.
Impact
Confidentiality is compromised as attackers can retrieve arbitrary files, potentially exposing credentials, database configs, or source code. Integrity is at risk if sensitive files are modified via other vulnerabilities. Availability is not directly impacted. Site administrators and owners are the primary defenders who must address this issue.
Remediation
Upgrade Loco Translate to version 2.8.9 or later. If upgrade is not immediately possible, disable the translator capability or restrict file access via .htaccess or server configuration. Monitor file access logs for suspicious activity and apply least privilege principles to user roles.
Risk context
The CVE has a medium severity score (CVSS 6.8) and a very low EPSS of 0.00157, indicating a low likelihood of exploitation but still requiring timely patching to prevent data exposure.
Affected products
- Loco Translate WordPress plugin
Scores
- Severity
- medium
- CVSS v2
- 6.1
- CVSS v3
- 6.8
- CVSS v4
- —
- EPSS
- 0.00157