rootpwn

high · CVSS v3 6.8 · EPSS 0.00152

CVE-2026-94239

The Loco Translate WordPress plugin (before v2.8.9) fails to sanitize bundle configuration values, enabling stored XSS via the admin interfa

Overview

The Loco Translate WordPress plugin (before v2.8.9) fails to sanitize bundle configuration values, enabling stored XSS via the admin interface. Attackers with translator or higher roles can inject malicious scripts that execute in the browsers of privileged users such as administrators. This flaw allows attackers to steal session cookies, deface content, or perform further privilege escalation.

Description

The Loco Translate WordPress plugin before 2.8.9 does not sanitise and escape some bundle configuration values before outputting them back in an admin page, allowing users with the translator capability and above to perform Stored Cross-Site Scripting attacks against high privilege users such as administrators.

Impact

Confidentiality: attackers can exfiltrate sensitive data from admin sessions. Integrity: malicious scripts can modify or delete content. Availability: repeated XSS can degrade user experience. The primary impact is on administrators and other high‑privilege users who view the vulnerable admin page.

Remediation

Update Loco Translate to version 2.8.9 or later, which sanitises bundle configuration values. If an update is not immediately possible, remove the translator capability from all non‑trusted users or restrict access to the affected admin page. Verify that the plugin’s output is properly escaped before rendering.

Risk context

Severity is high with a CVSS v3 score of 6.8 and an EPSS of 0.00152, indicating a low probability of exploitation but significant impact if triggered. Defenders should prioritize patching or mitigating the vulnerability promptly.

Affected products

  • WordPress Loco Translate

Scores

Severity
high
CVSS v2
8.3
CVSS v3
6.8
CVSS v4
—
EPSS
0.00152

wordpress plugin xss stored admin high-privilege cve-2026-94239

← All CVEs