CVE-2026-4146Disclosure

LOWCVSS 6.1 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Loco Translate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘update_href’ parameter in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-31); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-31: 2Mentions · 2026-04-01: 1PoC Mentioned / Linked · 2026-04-01: 1Technical Details · 2026-03-31: 2Technical Details · 2026-04-01: 103-3104-01
Signal classification3 categories
Disclosure
133.3%
General
133.3%
PoC
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-312
Disclosure1General1
2026-04-011
PoC1
Full discourse3 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-4146-loco-translate-version-2-8-2-medium-vulnerability-proof-of-concept CVE-2026-4146 #WordPress plugin #vulnerability loco-translate#cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    A proof‑of‑concept for CVE‑2026‑4146 in the WordPress plugin Loco Translate 2.8.2 has been posted, indicating a medium severity vulnerability, with no reported active exploitation or patch status.

    0000039
    5 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4146 The Loco Translate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘update_href’ parameter in all versions up to, and including, 2.8.2 due … https://www.cve.org/CVERecord?id=CVE-2026-4146

    Post summary

    The post reports a Reflected XSS vulnerability in Loco Translate up to v2.8.2, but provides no PoC, exploit, or mitigation details.

    0000073
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4146 - Loco Translate <= 2.8.2 - Reflected Cross-Site Scripting via 'update_href' Parameter Intel Report: https://ift.tt/dQ4TK1c

    Post summary

    The alert announces CVE-2026-4146, a reflected XSS vulnerability in Loco Translate 2.8.2 or earlier, but provides no PoC, exploit code, active exploitation evidence, or patch information.

    0000034
    281 followersView on X

Explore more