Known Vulnerabilities for Loco Translate by Loco Translate Project
Listed below are 2 of the newest known vulnerabilities associated with "Loco Translate" by "Loco Translate Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-15005 json | The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8... | Not Provided | 2026-07-16 | 2026-07-16 |
| CVE-2026-1921 json | The Loco Translate plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.8.2 via the `... | Not Provided | 2026-05-05 | 2026-05-05 |
| CVE-2022-0765 json | The Loco Translate WordPress plugin before 2.6.1 does not properly remove inline events from elements in the source translati... | 5.4 - MEDIUM | 2022-04-18 | 2022-04-27 |
| CVE-2021-24721 json | The Loco Translate WordPress plugin before 2.5.4 mishandles data inputs which get saved to a file, which can be renamed to an... | 6.5 - MEDIUM | 2021-11-08 | 2021-11-10 |