CVE Database /
CVE-2021-24721
CVE · Medium
CVE-2021-24721 — Loco Translate [loco-translate] < 2.5.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24721
|
Loco Translate [loco-translate] < 2.5.4 |
Improper Control of Generation of Code ('Code Injection') |
Medium
6.5
|
< 2.5.4
|
2.5.4 |
2021-10-11 |
—
|
CVE-2021-24721
Loco Translate versions prior to 2.5.4 contain a vulnerability where improperly validated input data can be written to files that may subsequently be renamed with .php extensions. This flaw allows users with translator-level privileges to execute arbitrary PHP code by placing malicious scripts into web-accessible directories, provided they can manipulate the file extension during the save process.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings