Sceawere

Vulnerability Detail

CVE-2026-94239UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Loco Translate Stored XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.8
Creation Date
13h ago
Vendor
Unknown
Product
Loco Translate
Attack Type
CWE-79 Cross-Site Scripting (XSS)
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Loco Translate WordPress plugin before 2.8.9 does not sanitise and escape some bundle configuration values before outputting them back in an admin page, allowing users with the translator capability and above to perform Stored Cross-Site Scripting attacks against high privilege users such as administrators.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.8",
  "pubDate": "2026-10-03T06:16:47.363Z",
  "pubdate": "2026-10-03T06:16:47.363Z",
  "executiveSummary": "The Loco Translate WordPress plugin, specifically versions prior to 2.8.9, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This security flaw originates from a failure to properly sanitize and escape bundle configuration values before they are rendered in the WordPress administrative interface.\nThe vulnerability allows an authenticated user assigned the 'translator' role or higher to inject malicious JavaScript payloads into the plugin's configuration settings. When an administrator or other high-privilege user views these compromised settings within the dashboard, the injected script executes within the context of their session. This effectively grants an attacker the ability to perform unauthorized actions on behalf of the victim, potentially leading to full site compromise, administrative account takeover, or session hijacking.\nGiven that the vulnerability resides within the administrative backend, it presents a significant risk to the integrity and confidentiality of the WordPress installation. Successful exploitation requires the attacker to possess at least the translator capability, making this an elevation-of-privilege vector that leverages trusted internal users to target administrative accounts.",
  "technicalDetails": "The root cause of this vulnerability is improper input validation and output encoding during the processing of bundle configuration parameters. The Loco Translate plugin stores user-defined configuration values associated with language bundles. When these values are retrieved from the database and rendered back into the HTML of the administration pages, the application fails to apply necessary sanitization or output escaping functions.\nAttackers with 'translator' privileges or higher can modify these bundle configuration fields to include arbitrary JavaScript payloads. By crafting a malicious string containing script tags or HTML event handlers (e.g., onerror, onload), an attacker can persist the code within the plugin's settings stored in the WordPress database.\nThe attack flow proceeds as follows: First, the authenticated attacker accesses the bundle configuration interface provided by Loco Translate. Second, the attacker submits a modified configuration containing the XSS payload. Third, the plugin saves this payload into the database without validation. Fourth, when an administrator navigates to the specific administrative page where these settings are rendered, the browser interprets the unsanitized input as executable script code.\nBecause the payload executes within the context of the administrator’s session, it inherits the administrator's cookies and permissions. This allows the attacker to execute arbitrary administrative tasks, such as creating new administrator accounts, modifying site settings, or installing malicious plugins. Since the vulnerability is stored, it remains dormant until triggered by an unsuspecting administrator, making it a persistent threat that does not require the attacker to be online at the time of execution.\nThe vulnerability affects all versions of the Loco Translate plugin prior to 2.8.9. As a backend-facing vulnerability, it is primarily restricted to the administrative dashboard, meaning an attacker must already have authenticated access to the system with sufficient privileges to modify plugin settings. The lack of output encoding (e.g., using esc_html() or esc_attr() in PHP) is the primary technical failure that allows the browser to misinterpret data as code."
}
CVE-2026-94239: Loco Translate Stored XSS Vulnerability (MEDIUM Severity, CVSS: 6.8) | Sceawere