Stored Cross-Site Scripting Vulnerability in Loco Translate Plugin for WordPress
CVE-2026-15066
6.4MEDIUM
What is CVE-2026-15066?
The Loco Translate plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) attacks due to inadequate input sanitization and output escaping mechanisms. Authenticated users with translator-level access or higher can exploit this vulnerability by injecting malicious scripts via PO File Extracted Comments. These scripts are executed when other users access affected pages, potentially compromising user data and site integrity.
Affected Version(s)
Loco Translate 0 <= 2.8.7