Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-94238 1 Wordpress-extensions 1 Loco Translate 2026-10-04 6.8 Medium
The Loco Translate WordPress plugin before 2.8.9 does not restrict which file paths its translation file routes will read, allowing users granted the Loco Translate WordPress plugin before 2.8.9's translator capability to retrieve the contents of files of certain types from anywhere on the server, including outside the web root.
CVE-2026-94239 1 Wordpress-extensions 1 Loco Translate 2026-10-04 6.8 Medium
The Loco Translate WordPress plugin before 2.8.9 does not sanitise and escape some bundle configuration values before outputting them back in an admin page, allowing users with the translator capability and above to perform Stored Cross-Site Scripting attacks against high privilege users such as administrators.