The Loco Translate plugin for WordPress is susceptible to a path traversal vulnerability via the `fsReference` AJAX route, allowing unauthorized file access. By exploiting this flaw, authenticated users with Translator-level access or above can traverse directories and read sensitive files on the server.
We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.