high · CVSS v3 6.8 · EPSS 0.00152
CVE-2026-94239
The Loco Translate WordPress plugin (before v2.8.9) fails to sanitize bundle configuration values, enabling stored XSS via the admin interfa
Overview
The Loco Translate WordPress plugin (before v2.8.9) fails to sanitize bundle configuration values, enabling stored XSS via the admin interface. Attackers with translator or higher roles can inject malicious scripts that execute in the browsers of privileged users such as administrators. This flaw allows attackers to steal session cookies, deface content, or perform further privilege escalation.
Description
The Loco Translate WordPress plugin before 2.8.9 does not sanitise and escape some bundle configuration values before outputting them back in an admin page, allowing users with the translator capability and above to perform Stored Cross-Site Scripting attacks against high privilege users such as administrators.
Impact
Confidentiality: attackers can exfiltrate sensitive data from admin sessions. Integrity: malicious scripts can modify or delete content. Availability: repeated XSS can degrade user experience. The primary impact is on administrators and other high‑privilege users who view the vulnerable admin page.
Remediation
Update Loco Translate to version 2.8.9 or later, which sanitises bundle configuration values. If an update is not immediately possible, remove the translator capability from all non‑trusted users or restrict access to the affected admin page. Verify that the plugin’s output is properly escaped before rendering.
Risk context
Severity is high with a CVSS v3 score of 6.8 and an EPSS of 0.00152, indicating a low probability of exploitation but significant impact if triggered. Defenders should prioritize patching or mitigating the vulnerability promptly.
Affected products
- WordPress Loco Translate
Scores
- Severity
- high
- CVSS v2
- 8.3
- CVSS v3
- 6.8
- CVSS v4
- —
- EPSS
- 0.00152