Input validation vulnerability in Loco Translate 2.6.9

The Loco Translate plugin for WordPress has a security vulnerability in versions up to 2.6.9. This is because the ‘init’ function does not properly check for a specific security code. This means that someone who is not logged in can manipulate the plugin and make changes without permission, as long as they can trick the website administrator into doing something like clicking on a link.

Detected in:

Loco Translate fixed vulnerable versions: >= * <= 2.6.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.