CVE-2026-94238 - Loco Translate < 2.8.9 - Translator+ Limited File Read via 'path' Parameter
CVE ID :CVE-2026-94238
Published : Oct. 3, 2026, 6:16 a.m. | 57 minutes ago
Description :The Loco Translate WordPress plugin before 2.8.9 does not restrict which file paths its translation file routes will read, allowing users granted the Loco Translate WordPress plugin before 2.8.9's translator capability to retrieve the contents of files of certain types from anywhere on the server, including outside the web root.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 3, 2026, 6:16 a.m. | 57 minutes ago
Description :The Loco Translate WordPress plugin before 2.8.9 does not restrict which file paths its translation file routes will read, allowing users granted the Loco Translate WordPress plugin before 2.8.9's translator capability to retrieve the contents of files of certain types from anywhere on the server, including outside the web root.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...