Skip to content

Known CVE

WordPress Loco Translate < 2.6.1 - Cross-Site Scripting

Loco Translate WordPress plugin before 2.6.1 contains a stored cross-site scripting vulnerability caused by improper removal of inline events from source translation strings, allowing authenticated users to inject arbitrary JavaScript payloads.

CVE-2022-0765

Medium2022CVSS 5.4CWE-79

cve2022 · wordpress · wp · wp-plugin · xss · loco-translate · authenticated

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website