Loco Translate WordPress plugin before 2.6.1 contains a stored cross-site scripting vulnerability caused by improper removal of inline events from source translation strings, allowing authenticated users to inject arbitrary JavaScript payloads.
id: CVE-2022-0765
info:
name: WordPress Loco Translate < 2.6.1 - Cross-Site Scripting
author: 0
...