Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Loco Translate — verificado contra la base de datos de seguridad local de WP Clinic.
Qué hace este plugin
- Slug:
loco-translate
- 1000000+ instalaciones activas
i18nl10nlanguagemultilingualtranslation
Estado de mantenimiento
- Última versión conocida: 2.8.7
- Requiere PHP: 7.4+
- PHP máximo soportado (analizado): 8.4
Vulnerabilidades conocidas
6 CVEs conocidos registrados para Loco Translate.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2026-15005
|
Loco Translate [loco-translate] < 2.8.6 |
Falsificación de petición en sitios cruzados (CSRF) |
Alta
8,8
|
< 2.8.6
|
2.8.6 |
2026-07-15 |
✓ corregido en la última versión
|
|
CVE-2026-1921
|
Loco Translate [loco-translate] < 2.8.3 |
Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) |
Media
4,9
|
< 2.8.3
|
2.8.3 |
2026-05-04 |
✓ corregido en la última versión
|
|
CVE-2024-37236
|
Loco Translate [loco-translate] < 2.6.10 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
4,3
|
< 2.6.10
|
2.6.10 |
2024-06-21 |
✓ corregido en la última versión
|
|
CVE-2022-0765
|
Loco Translate [loco-translate] < 2.6.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 2.6.1
|
2.6.1 |
2022-03-22 |
✓ corregido en la última versión
|
|
CVE-2021-24721
|
Loco Translate [loco-translate] < 2.5.4 |
Control incorrecto de la generación de código (inyección de código) |
Media
6,5
|
< 2.5.4
|
2.5.4 |
2021-10-11 |
✓ corregido en la última versión
|
|
CVE-2026-4146
|
Loco Translate [loco-translate] < 2.8.3 |
— |
Desconocido
|
< 2.8.3
|
2.8.3 |
0000-00-00 |
✓ corregido en la última versión
|
|
—
|
Loco Translate [loco-translate] < 2.2.2 |
— |
Desconocido
|
< 2.2.2
|
2.2.2 |
— |
✓ corregido en la última versión
|
CVE-2026-15005
The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing or incorrect nonce validation on the execTemplate function. This makes it possible for unauthenticated attackers to execute arbitrary PHP code on the server by supplying a php://filter stream wrapper URI as the 'template' parameter, which bypasses path validation and is passed directly to the include sink in execTemplate() via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2026-1921
The Loco Translate plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.8.2 via the `fsReference` AJAX route. This is due to the `findSourceFile()` method normalizing user-supplied `ref` paths containing `../` directory traversal sequences without validating that the resolved path remains within the intended bundle or content directory. This makes it possible for authenticated attackers, with Translator-level access and above (custom `loco_admin` capability required, granted to the `translator` role and administrators by default), to read arbitrary `.php`, `.js`, `.json`, and `.twig` files from the server filesystem outside the intended translation directory. Files named wp-config.php are excluded.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-37236
The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.9. This is due to missing or incorrect nonce validation on the 'init' function. This makes it possible for unauthenticated attackers to save or delete a configuration via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2022-0765
The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via elements in versions up to, and including, 2.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the plugin, such as translators and site administrators, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2021-24721
The Loco Translate WordPress plugin before 2.5.4 mishandles data inputs which get saved to a file, which can be renamed to an extension ending in .php, resulting in authenticated "translator" users being able to inject PHP code into files ending with .php in web accessible locations.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2026-4146
The Loco Translate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘update_href’ parameter in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Loco Translate [loco-translate] < 2.2.2
WordPress plugin Loco Translate version appears to have an Authenticated LFI Vulnerability under the 'Edit Template' Functionality.
The following vulnerability can be exploited by any user with access to the plugin (access can range from Admin to Subscriber)
WPScanTeam Note: Was not able to reproduce this issue with any user other than admin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Cómo solucionarlo
Mantén Loco Translate actualizado — 2.8.7 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Alternativas más seguras / más establecidas