What is CVE-2026-15066?
This vulnerability in the Loco Translate plugin for WordPress allows Stored Cross-Site Scripting (XSS) attacks via extracted comments from PO files. It affects all versions up to and including 2.8.7 and can be exploited by authenticated attackers with translator-level access. Immediate update to the latest version is required.
Azərbaycanca: Bu zəiflik WordPress-in Loco Translate plaginində aşkarlanıb və PO faylından çıxarılan şərhlər vasitəsilə Stored Cross-Site Scripting (XSS) hücumlarına imkan verir. 2.8.7 daxil olmaqla bütün versiyalara təsir edir və tərcüməçi səviyyəsində girişi olan autentifikasiya olunmuş hücumçular tərəfindən istifadə oluna bilər. Plagin dərhal son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Loco Translate plugin are affected by CVE-2026-15066?
This vulnerability affects all versions of the Loco Translate plugin up to and including 2.8.7.
What level of access does an attacker need to exploit CVE-2026-15066?
An attacker must be an authenticated user with translator-level access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.