Skip to content
CVE / MITRECVE RecentΒ·Β·1 min read

CVE-2026-15005 - Loco Translate <= 2.8.5 - Cross-Site Request Forgery to Remote Code Execution via 'template' Parameter

CVE ID :CVE-2026-15005 Published : July 16, 2026, 8:26 a. m. | 32 minutes ago Description :The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.

8. 5. This is due to missing or incorrect nonce validation on the execTemplate function.

Originally reported by CVE Recent
0 comments

0 comments

Posting as NimbleAxolotl898
0/1000

No comments yet. Be the first to start the discussion.