CVE-2026-15005
The Loco Translate plugin for WordPress has a vulnerability in versions up to 2.8.5 that allows an attacker to execute arbitrary PHP code on the server. This occurs because the plugin does not properly validate the 'template' parameter in the execTemplate function, which can be manipulated by an attacker to bypass security checks and inject malicious code. An attacker can exploit this vulnerability by tricking a site administrator into performing a specific action, such as clicking on a link, which can lead to the execution of arbitrary PHP code.
Based on public CVE data (MITRE/NVD).