PT-2022-13421 · WordPress · Loco Translate

Taurus Omar

·

Published

2022-04-18

·

Updated

2025-12-24

·

CVE-2022-0765

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Loco Translate WordPress plugin versions prior to 2.6.1
Description The issue allows any user with access to the plugin, such as Translator and Administrator, to add arbitrary javascript payloads to the source strings, leading to a stored cross-site scripting (XSS) vulnerability. This occurs because the plugin does not properly remove inline events from elements in the source translation strings before outputting them in the editor in the plugin admin panel.
Recommendations For versions prior to 2.6.1, update to version 2.6.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin admin panel to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-0765

Affected Products

Loco Translate