Description
The Loco Translate WordPress plugin before 2.8.9 does not sanitise and escape some bundle configuration values before outputting them back in an admin page, allowing users with the translator capability and above to perform Stored Cross-Site Scripting attacks against high privilege users such as administrators.
Published: 2026-10-03
Score: n/a
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The Loco Translate WordPress plugin contains a stored cross‑site scripting flaw because it does not sanitise and escape certain bundle configuration values before outputting them on an admin page. Users who have the translator capability or higher can inject malicious scripts that will execute in the browsers of other privileged users when they view the admin interface, potentially allowing attackers to deface pages, steal session data, or perform other malicious actions that compromise confidentiality and integrity.

Affected Systems

The vulnerability affects the Loco Translate plugin for WordPress. Any installed instance running a version earlier than 2.8.9 is at risk. Systems with WordPress installations that have this plugin deployed should verify the version number and apply the fix if required.

Risk and Exploitability

The attack vector requires a user with translator-level or higher privileges to input malicious configuration data, which is then stored and later rendered without sanitisation. The description indicates that such users are common in many WordPress environments, so, based on this inference, the likelihood of exploitation is moderate, though no EPSS score is available. The vulnerability is not listed in CISA’s KEV catalog, and no CVSS score is provided; however, its ability to target high‑privilege administrators makes it a high‑severity concern.

Generated by OpenCVE AI on October 3, 2026 at 07:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Loco Translate plugin to version 2.8.9 or later, which includes proper input sanitisation and output escaping.
  • If an upgrade is not immediately feasible, restrict the translator capability or remove any custom bundle configuration entries that can accept arbitrary input, thereby preventing the injection vector.
  • Implement a code review or automated static analysis on the plugin source to confirm that all configuration output is properly escaped before rendering.
  • Consider disabling or limiting the use of the bundle configuration feature until the issue is addressed, and monitor user activity logs for abnormal script injection attempts.

Generated by OpenCVE AI on October 3, 2026 at 07:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sat, 03 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Loco Translate WordPress plugin before 2.8.9 does not sanitise and escape some bundle configuration values before outputting them back in an admin page, allowing users with the translator capability and above to perform Stored Cross-Site Scripting attacks against high privilege users such as administrators.
Title Loco Translate < 2.8.9 - Translator+ Stored XSS via Bundle Configuration
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-03T06:00:27.879Z

Reserved: 2026-09-21T08:00:53.157Z

Link: CVE-2026-94239

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:47.363

Modified: 2026-10-03T06:16:47.363

Link: CVE-2026-94239

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T08:00:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')