Impact
The Loco Translate WordPress plugin contains a stored cross‑site scripting flaw because it does not sanitise and escape certain bundle configuration values before outputting them on an admin page. Users who have the translator capability or higher can inject malicious scripts that will execute in the browsers of other privileged users when they view the admin interface, potentially allowing attackers to deface pages, steal session data, or perform other malicious actions that compromise confidentiality and integrity.
Affected Systems
The vulnerability affects the Loco Translate plugin for WordPress. Any installed instance running a version earlier than 2.8.9 is at risk. Systems with WordPress installations that have this plugin deployed should verify the version number and apply the fix if required.
Risk and Exploitability
The attack vector requires a user with translator-level or higher privileges to input malicious configuration data, which is then stored and later rendered without sanitisation. The description indicates that such users are common in many WordPress environments, so, based on this inference, the likelihood of exploitation is moderate, though no EPSS score is available. The vulnerability is not listed in CISA’s KEV catalog, and no CVSS score is provided; however, its ability to target high‑privilege administrators makes it a high‑severity concern.
OpenCVE Enrichment