Sceawere

Vulnerability Detail

CVE-2026-94238UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Loco Translate Arbitrary File Read

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.8
Creation Date
13h ago
Vendor
Unknown
Product
Loco Translate
Attack Type
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Loco Translate WordPress plugin before 2.8.9 does not restrict which file paths its translation file routes will read, allowing users granted the Loco Translate WordPress plugin before 2.8.9's translator capability to retrieve the contents of files of certain types from anywhere on the server, including outside the web root.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.8",
  "pubDate": "2026-10-03T06:16:47.123Z",
  "pubdate": "2026-10-03T06:16:47.123Z",
  "executiveSummary": "The Loco Translate WordPress plugin, specifically versions prior to 2.8.9, is susceptible to an Arbitrary File Read vulnerability caused by insufficient input sanitization of file paths within its translation file routing mechanisms.\nThis vulnerability allows an attacker possessing the 'translator' capability to perform directory traversal and read sensitive files from the underlying server filesystem, including files located outside the web root directory.\nThe primary risk implications involve the potential exposure of configuration files (such as wp-config.php), sensitive environment variables, system credentials, or proprietary source code.\nExploitation requires an attacker to be authenticated with the 'translator' privilege, which is a specific capability defined by the plugin within the WordPress environment.\nThe vulnerability represents a critical breakdown in access control and file system isolation, granting the attacker unauthorized read access to system-level files, significantly increasing the probability of full server compromise or privilege escalation.",
  "technicalDetails": "The vulnerability stems from improper validation and sanitization of user-supplied input used in file path construction within the Loco Translate plugin's file handling routes. Specifically, the plugin fails to implement adequate directory traversal protection (e.g., filtering for '../' sequences) or path normalization when processing requests for translation files.\nThe root cause is the reliance on insecure input parameters that are subsequently utilized in file system API calls without ensuring the target path resides within the intended, restricted directory scope.\nAn authenticated user assigned the 'translator' capability can manipulate the path parameters in affected API requests to traverse the directory structure of the host server.\nThe attack flow proceeds as follows: 1) The authenticated attacker identifies the translation file retrieval endpoint within the Loco Translate plugin. 2) The attacker crafts a request containing a malicious path parameter utilizing directory traversal sequences (e.g., '../../../../etc/passwd'). 3) The application server receives this path and, due to the lack of validation, resolves the path to a location outside the plugin's intended directory. 4) The application reads the contents of the target file and returns the data to the attacker, typically in the response body.\nBecause the plugin does not enforce strict path constraints, any file the web server process has read permissions for—including sensitive system files, configuration files containing database credentials, or cryptographic keys—is potentially accessible.\nThis vulnerability is particularly dangerous because it bypasses standard WordPress file access restrictions. The limitation to the 'translator' capability represents the primary authentication requirement, but within the context of a multi-user WordPress installation, this scope is sufficient for an attacker to escalate their access, gather intelligence for further attacks, or exfiltrate sensitive application data. The impact is essentially total data exposure for any file readable by the web server user."
}
CVE-2026-94238: Loco Translate Arbitrary File Read (MEDIUM Severity, CVSS: 6.8) | Sceawere