cleantalk
Vulnerabilities and Security Researches

Loco Translate, CVE-2026-94238

CVE, Research URL

CVE-2026-94238

Application

Loco Translate

Published on
Oct 03, 2026
Research Description
The Loco Translate WordPress plugin before 2.8.9 does not restrict which file paths its translation file routes will read, allowing users granted the Loco Translate WordPress plugin before 2.8.9's translator capability to retrieve the contents of files of certain types from anywhere on the server, including outside the web root.
Affected versions
max 2.8.9.
Status
vulnerable