CVE-2026-15066: Loco Translate <= 2.8.7 - Authenticated (Translator+) Stored Cross-Site Scripting via PO File Extracted Comments
The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in all versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with translator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15066?
The severity of CVE-2026-15066 is rated as medium with a score of 6.4.
How do I fix CVE-2026-15066?
To fix CVE-2026-15066, update the Loco Translate plugin to version 2.8.8 or higher.
What type of vulnerability is CVE-2026-15066?
CVE-2026-15066 is a Stored Cross-Site Scripting (XSS) vulnerability.
Who is affected by CVE-2026-15066?
Authenticated users with translator-level access to the Loco Translate plugin are affected by CVE-2026-15066.
What can attackers do with CVE-2026-15066?
Attackers can exploit CVE-2026-15066 to inject malicious scripts into PO file extracted comments that can execute when viewed by other users.