The Loco Translate WordPress plugin before 2.8.9 does not sanitise and escape some bundle configuration values before outputting them back in an admin page, allowing users with the translator capability and above to perform Stored Cross-Site Scripting attacks against high privilege users such as administrators. This vulnerability requires verification of the Loco Translate plugin version and monitoring of [truncated]
The Loco Translate WordPress plugin before 2.8.9 has a vulnerability allowing users with translator capability to read files from anywhere on the server, including outside the web root. This issue can lead to potential unauthorized file disclosure and information leakage about server configuration or sensitive data. Defenders managing WordPress installations with the Loco Translate plugin, especially thos [truncated]