← back
CVE-2026-94238mediumCWE-22

Loco Translate < 2.8.9 - Translator+ Limited File Read via 'path' Parameter

33Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 6.8epss 0.3%
exploitation probability
0.3%top 78% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Loco Translate WordPress plugin before 2.8.9 does not restrict which file paths its translation file routes will read, allowing users granted the Loco Translate WordPress plugin before 2.8.9's translator capability to retrieve the contents of files of certain types from anywhere on the server, including outside the web root.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Affected products
Unknown · Loco Translate
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.