S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 24, 2025

CVE-2022-0765 Scanner

CVE-2022-0765 Scanner - Cross-Site Scripting vulnerability in WordPress Loco Translate

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0765
5.4
CVSS

The Loco Translate WordPress plugin before 2.6.1 does not properly remove inline events from elements in the source translation strings before outputting them in the editor in the plugin admin panel, allowing any user with access to the plugin (Translator and Administrator by default) to add arbitrary javascript payloads to the source strings leading to a stored cross-site scripting (XSS) vulnerability.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Loco Translate
AFFECTED< 2.6.1SAFE ✓≥ 2.6.1
Updated Aug 22, 2026View on NVD →
Detail

WordPress Loco Translate is a widely used plugin for translating and managing localizations in WordPress sites. It is popular among developers and site administrators for managing language translation files directly within WordPress. Users leverage this plugin to handle translation project files in an organized manner. The plugin streamlines the translation process for various WordPress themes and plugins, enhancing multilingual capabilities. Besides its utility to bridge language gaps, users appreciate its ability to integrate seamlessly into existing workflows. The Loco Translate plugin is essential for anyone looking to manage translations effectively on WordPress.

The Cross-Site Scripting (XSS) vulnerability in WordPress Loco Translate before version 2.6.1 arises due to improper removal of inline events from source translation strings. XSS vulnerabilities enable attackers to inject malicious scripts into web pages viewed by other users. If exploited, this vulnerability allows authenticated users to insert arbitrary JavaScript into the admin panel. This can potentially lead to session hijacking or site defacement. It represents a significant security flaw in web applications that manage sensitive user data.

This vulnerability resides in the way WordPress Loco Translate processes certain inputs within translation strings. The improper handling of these strings facilitates the execution of unauthorized scripts. Attackers can manipulate the 'save' functionality that uses the extracted 'loco-nonce' to execute unauthorized actions. The core issue is the lack of stringent input validation and sanitization for data within locale paths and filenames. By delivering a script through crafted translation data, this weakness in the plugin lets attackers execute scripts in the admin's browser context.

When malicious actors exploit this Cross-Site Scripting vulnerability, they can execute scripts in the context of the admin panel. This can lead to critical security breaches such as session hijacking, where attackers gain unauthorized access to user sessions. It could also allow for site defacement by altering web page content displayed to users. Persistent XSS, like in this scenario, can propagate the attacker's code across multiple user sessions. Additionally, sensitive data could be exfiltrated, undermining user privacy and site integrity.

REFERENCES

Solution Advice
  • Update WordPress Loco Translate to version 2.6.1 or later.
  • Implement input validation and sanitization routines to ensure proper handling of user input.
  • Conduct regular security audits to identify and mitigate XSS vulnerabilities on your site.
  • Restrict admin panel access to trusted users and monitor user activities for suspicious behavior.
  • Consider implementing Content Security Policy (CSP) to further reduce XSS risks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.