CVE-2026-94239 - CERT CVE
ID CVE-2026-94239
Sažetak The Loco Translate WordPress plugin before 2.8.9 does not sanitise and escape some bundle configuration values before outputting them back in an admin page, allowing users with the translator capability and above to perform Stored Cross-Site Scripting attacks against high privilege users such as administrators.
Reference
CVSS
Base: 6.8
Impact: 5.9
Exploitability:0.9
Pristup
VektorSloženostAutentikacija
NETWORK LOW HIGH
Impact
PovjerljivostCjelovitostDostupnost
HIGH HIGH HIGH
CVSS vektor CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Zadnje važnije ažuriranje 03-10-2026 - 16:16
Objavljeno 03-10-2026 - 06:16