File Path Exposure in Loco Translate Plugin for WordPress
CVE-2026-94238
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 3 October 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-94238?
The Loco Translate plugin for WordPress, prior to version 2.8.9, contains a vulnerability that permits users with translator capabilities to access and read sensitive files from arbitrary paths on the server. This flaw allows unauthorized access to information outside the intended web root, potentially exposing critical data and compromising the system's integrity.
Affected Version(s)
Loco Translate 0 < 2.8.9
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.