PatchSiren

Loco Translate CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Loco Translate CVE published 2026-10-03

CVE-2026-94239

The Loco Translate WordPress plugin before 2.8.9 does not sanitise and escape some bundle configuration values before outputting them back in an admin page, allowing users with the translator capability and above to perform Stored Cross-Site Scripting attacks against high privilege users such as administrators. This vulnerability requires verification of the Loco Translate plugin version and monitoring of [truncated]

Review Loco Translate CVE published 2026-10-03

CVE-2026-94238

The Loco Translate WordPress plugin before 2.8.9 has a vulnerability allowing users with translator capability to read files from anywhere on the server, including outside the web root. This issue can lead to potential unauthorized file disclosure and information leakage about server configuration or sensitive data. Defenders managing WordPress installations with the Loco Translate plugin, especially thos [truncated]