Known Vulnerabilities for Loco Translate by Unknown
Listed below are 4 of the newest known vulnerabilities associated with "Loco Translate" by "Unknown".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-94239 json | The Loco Translate WordPress plugin before 2.8.9 does not sanitise and escape some bundle configuration values before outputt... | Not Provided | 2026-10-03 | 2026-10-03 |
| CVE-2026-94238 json | The Loco Translate WordPress plugin before 2.8.9 does not restrict which file paths its translation file routes will read, al... | Not Provided | 2026-10-03 | 2026-10-03 |
| CVE-2026-15066 json | The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in all ve... | Not Provided | 2026-08-16 | 2026-08-17 |
| CVE-2026-15005 json | The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8... | Not Provided | 2026-07-16 | 2026-07-16 |