Reflected Cross-Site Scripting Vulnerability in Loco Translate for WordPress
CVE-2026-4146
6.1MEDIUM
What is CVE-2026-4146?
The Loco Translate plugin for WordPress, up to version 2.8.2, is prone to a reflected cross-site scripting (XSS) vulnerability due to inadequate input validation and output escaping processes in the 'update_href' parameter. This flaw allows unauthenticated attackers to embed and execute arbitrary web scripts on user browsers by deceiving them into clicking malicious links. Users must ensure they upgrade to the latest version to mitigate the risks associated with this vulnerability.
Affected Version(s)
Loco Translate 0 <= 2.8.2