PT-2026-29193 · WordPress · Loco Translate

Jack Pas

·

Publicado

2026-03-31

·

Atualizado

2026-03-31

·

CVE-2026-4146

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Loco Translate versions up to and including 2.8.2
Description The Loco Translate plugin for WordPress is susceptible to Reflected Cross-Site Scripting through the update href parameter due to inadequate input sanitization and output escaping. This allows unauthenticated attackers to inject arbitrary web scripts into pages, potentially leading to execution if a user is tricked into performing an action like clicking a malicious link. The vulnerable parameter is update href.
Recommendations Update Loco Translate to a version later than 2.8.2.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-4146

Produtos afetados

Loco Translate