Impact
The Loco Translate plugin for WordPress contains a stored cross‑site scripting flaw that enables an authenticated translator or higher to insert arbitrary JavaScript into PO file extracted comments. Because the plugin trusts the comment text when generating the translation interface, a malicious commenter can embed scripts that will run in the browsing context of any visitor to the translated page, potentially hijacking sessions, stealing credentials, or defacing content.
Affected Systems
WordPress sites that have the Loco Translate plugin installed, version 2.8.7 or earlier, which is maintained by Tim Whitlock. These sites expose the vulnerable comment input to users with translator‑level permissions and above.
Risk and Exploitability
The flaw carries a CVSS score of 6.4, denoting moderate severity, and has no EPSS value available, so the likelihood of exploitation is uncertain but not negligible. The plugin is not listed in the CISA KEV catalogue, suggesting no known widespread public exploits as of the data timestamp. Attackers must first authenticate with translator or higher role and inject malicious code into the PO file comment field; thereafter the code executes in the browsers of any user who views the affected translated content.
OpenCVE Enrichment