WordPress Plugin Loco Translate PHP Code Injection (2.5.3)
Description
WordPress Plugin Loco Translate is prone to a vulnerability that lets attackers inject and execute arbitrary code because the application fails to sanitize user-supplied input. Attackers can exploit this issue to execute arbitrary PHP code within the context of the affected webserver process. WordPress Plugin Loco Translate version 2.5.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.5.4 or latest