PLUGIN SECURITY

Is Loco Translate safe?

Translate WordPress plugins and themes directly in your browser. Versatile PO file editor with integrated AI translation providers.

What this plugin does

  • Slug: loco-translate
  • Author: Tim W
  • 1000000+ active installs
  • 96/100 rating (452 reviews on wordpress.org)
  • 37950278 all-time downloads
  • On WordPress.org since 2013-07-23

i18nl10nlanguagemultilingualtranslation

Maintenance status

  • Latest known version: 2.8.8
  • Last updated: 2026-08-01 2:21pm GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

7 known CVEs on file for Loco Translate.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15066 Loco Translate [loco-translate] < 2.8.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 2.8.8 2.8.8 2026-08-15 ✓ fixed in latest
CVE-2026-15005 Loco Translate [loco-translate] < 2.8.6 Cross-Site Request Forgery (CSRF) High 8.8 < 2.8.6 2.8.6 2026-07-15 ✓ fixed in latest
CVE-2026-1921 Loco Translate [loco-translate] < 2.8.3 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 4.9 < 2.8.3 2.8.3 2026-05-04 ✓ fixed in latest
CVE-2024-37236 Loco Translate [loco-translate] < 2.6.10 Cross-Site Request Forgery (CSRF) Medium 4.3 < 2.6.10 2.6.10 2024-06-21 ✓ fixed in latest
CVE-2022-0765 Loco Translate [loco-translate] < 2.6.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.6.1 2.6.1 2022-03-22 ✓ fixed in latest
CVE-2021-24721 Loco Translate [loco-translate] < 2.5.4 Improper Control of Generation of Code ('Code Injection') Medium 6.5 < 2.5.4 2.5.4 2021-10-11 ✓ fixed in latest
Loco Translate [loco-translate] < 2.8.3 Unknown < 2.8.3 2.8.3 0000-00-00 ✓ fixed in latest
Loco Translate [loco-translate] < 2.2.2 Unknown < 2.2.2 2.2.2 ✓ fixed in latest
+ 2 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
Loco Translate < 2.2.2 - Authenticated LFI Unknown < 2.2.2 2.2.2 ✓ fixed in latest
CVE-2026-4146 Loco Translate < 2.8.3 - Reflected XSS via 'update_href' Parameter Unknown < 2.8.3 2.8.3 ✓ fixed in latest

How to fix it

Keep Loco Translate updated — 2.8.8 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.