在 Loco Translate WordPress 插件版本低于 2.8.9 中,该插件在将某些捆绑配置值输出到后台管理页面之前,未对其进行适当的过滤和转义处理。这使得具备翻译员权限及以上的用户能够对高权限用户(如管理员)发起存储型跨站脚本(Stored XSS)攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Loco Translate | 0 ~ 2.8.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86832 | MetForm < 4.3.1 - Unauthenticated Form Entry Data Disclosure via REST API | |
| CVE-2026-101159 | WP Ultimate Review < 2.4.4 - Unauthenticated Stored XSS via Review Submission | |
| CVE-2026-101160 | WP Ultimate Review < 2.4.4 - Unauthenticated DoS via Non-Numeric Review Rating | |
| CVE-2026-80518 | WP Ultimate CSV Importer < 9.2 - Unauthenticated Imported Data Disclosure via Predictable | |
| CVE-2026-80517 | WP Ultimate CSV Importer 7.17 - 9.1 - Admin+ Stored XSS via ZIP Import SVG Upload | |
| CVE-2026-101161 | WP Ultimate Review < 2.4.4 - Unauthenticated DoS via Unset Display Settings in wp-reviews | |
| CVE-2026-101162 | WP Ultimate Review < 2.4.4 - Author+ Stored XSS via Review Overview Settings | |
| CVE-2026-103293 | MPG < 4.2.3 - Editor+ Arbitrary File Read via Project Import | |
| CVE-2026-103514 | WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via TOTP Code Replay | |
| CVE-2026-86834 | MetForm 2.2.1 - 4.3.0 - Unauthenticated Debug File Disclosure via HubSpot Forms Integratio | |
| CVE-2026-94238 | Loco Translate < 2.8.9 - Translator+ Limited File Read via 'path' Parameter | |
| CVE-2026-85015 | Unlimited Elements For Elementor < 2.0.21 - Authenticated Arbitrary File Write via Path Tr | |
| CVE-2026-85568 | Unlimited Elements For Elementor 1.5.139 - 2.0.20 - Unauthenticated SQLi via 'ucs' Paramet | |
| CVE-2026-91078 | TillKit < 1.0.5 - Unauthenticated POS Takeover via Hard-Coded Default Manager PIN | |
| CVE-2026-88782 | Kubio AI Page Builder < 2.9.3 - Contributor+ Stored XSS via Image Gallery Item URL Attribu | |
| CVE-2026-88783 | Kubio AI Page Builder < 2.9.3 - Unauthenticated Stored XSS via Comment Content | |
| CVE-2026-92437 | Mailchimp for WooCommerce < 6.3 - Unauthenticated Abandoned Cart Modification and Deletion | |
| CVE-2026-89236 | SaveTo Wishlist Lite < 1.1.5 - Unauthenticated SQLi via 'sort_column' and 'sort_order' Par | |
| CVE-2026-96962 | Pie Register < 3.8.4.14 - Unauthenticated User Email Disclosure via Invitation Code | |
| CVE-2026-92923 | Unlimited Elements For Elementor 1.5.142 - 2.0.20 - Subscriber+ SQLi via get_addon_output_ |
No comments yet