---
id: CVE-2026-15066
title: >-
  The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site
  Scripting via PO File Extracted Comments in all versions up to, and including,
  2.8.7 due to insufficient input sanitization and output escaping
summary: >-
  The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site
  Scripting via PO File Extracted Comments in all versions up to, and including,
  2.8.7 due to insufficient input sanitization and output escaping. This makes
  it pos…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2026-08-16'
updated: '2026-08-16'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15066'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/loco-translate/tags/2.8.4/pub/js/min/admin.js#L1404
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/loco-translate/tags/2.8.4/pub/js/min/admin.js#L3533
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/loco-translate/tags/2.8.4/src/ajax/SaveController.php#L52
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/loco-translate/tags/2.8.5/pub/js/min/admin.js#L1404
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/loco-translate/tags/2.8.5/pub/js/min/admin.js#L3533
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/loco-translate/tags/2.8.5/src/ajax/SaveController.php#L52
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&old=3631056%40loco-translate&new=3631056%40loco-translate
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/9571a2f3-d148-4e9b-8837-b8d212418613?source=cve
    label: security@wordfence.com
tags:
  - nvd
ingestedAt: '2026-08-16T13:39:06.842Z'
epss: 0.00254
epssPercentile: 0.17262
---

## Overview

The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in all versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with translator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
