CVE · Medium

CVE-2026-15066 — Loco Translate [loco-translate] < 2.8.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15066 Loco Translate [loco-translate] < 2.8.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 2.8.8 2.8.8 2026-08-15

CVE-2026-15066

The Loco Translate plugin for WordPress contains a vulnerability that allows attackers with translator-level access to inject malicious code into translated content. This code can then be executed when a user views the affected page, potentially leading to unauthorized actions or data theft. The issue arises from inadequate filtering of user input and insufficient protection against cross-site scripting attacks.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.