CVE · High

CVE-2026-15005 — Loco Translate [loco-translate] < 2.8.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15005 Loco Translate [loco-translate] < 2.8.6 Cross-Site Request Forgery (CSRF) High 8.8 < 2.8.6 2.8.6 2026-07-15

CVE-2026-15005

The Loco Translate plugin for WordPress has a vulnerability in versions up to 2.8.5 that allows an attacker to execute arbitrary PHP code on the server. This occurs because the plugin does not properly validate the 'template' parameter in the execTemplate function, which can be manipulated by an attacker to bypass security checks and inject malicious code. An attacker can exploit this vulnerability by tricking a site administrator into performing a specific action, such as clicking on a link, which can lead to the execution of arbitrary PHP code.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.