vulnerability

WordPress Plugin: loco-translate: CVE-2021-24721: Improper Control of Generation of Code ('Code Injection')

Severity
4
CVSS
(AV:N/AC:L/Au:S/C:N/I:P/A:N)
Published
Oct 11, 2021
Added
May 15, 2025
Modified
Apr 29, 2026

Description

The Loco Translate WordPress plugin before 2.5.4 mishandles data inputs which get saved to a file, which can be renamed to an extension ending in .php, resulting in authenticated "translator" users being able to inject PHP code into files ending with .php in web accessible locations.

Solution

loco-translate-plugin-cve-2021-24721
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.