Loco Translate, CVE-2021-24721
- CVE, Research URL
- Home page URL
- Application
- Published on
- Nov 08, 2021
- Research Description
- The Loco Translate WordPress plugin before 2.5.4 mishandles data inputs which get saved to a file, which can be renamed to an extension ending in .php, resulting in authenticated "translator" users being able to inject PHP code into files ending with .php in web accessible locations.
- Affected versions
-
Min -, max 2.5.4.
- Status
-
vulnerable