vulnerability

WordPress Plugin: loco-translate: CVE-2021-24721: Improper Control of Generation of Code ('Code Injection')

Severity
4
CVSS
(AV:N/AC:L/Au:S/C:N/I:P/A:N)
Published
Oct 11, 2021
Added
May 15, 2025
Modified
Jun 24, 2025

Description

The Loco Translate WordPress plugin before 2.5.4 mishandles data inputs which get saved to a file, which can be renamed to an extension ending in .php, resulting in authenticated "translator" users being able to inject PHP code into files ending with .php in web accessible locations.

Solution

loco-translate-plugin-cve-2021-24721
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.