CVE · Medium

CVE-2024-37236 — Loco Translate [loco-translate] < 2.6.10

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-37236 Loco Translate [loco-translate] < 2.6.10 Cross-Site Request Forgery (CSRF) Medium 4.3 < 2.6.10 2.6.10 2024-06-21

CVE-2024-37236

The Loco Translate plugin for WordPress through version 2.6.9 contains a cross-site request forgery vulnerability in the 'init' function resulting from inadequate nonce verification. Unauthenticated attackers can exploit this flaw to modify or remove plugin configurations by deceiving a site administrator into clicking a malicious link. The vulnerability has been addressed in version 2.6.10 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.