天下漏洞,尽知其名
MEDIUM

CVE-2026-94238 Loco Translate 任意文件读取漏洞

影响具备翻译权限的用户可读取服务器任意位置特定类型文件

AI 研判

Loco Translate 是 WordPress 的翻译管理插件。其 2.8.9 之前版本未对翻译文件读取路由的路径做限制,导致拥有翻译权限的用户可读取服务器上任意位置的文件。该漏洞 CVSS 评分为 6.8,属中危。

影响范围

Loco Translate

Loco Translate WordPress 插件 2.8.9 之前的版本。

漏洞详情

漏洞类型为路径遍历导致的任意文件读取。插件在处理翻译文件读取请求时未校验用户提交的文件路径,未限制其只能访问插件允许的目录,从而可跳出 Web 根目录读取服务器上特定类型的文件。攻击者需先获得插件授予的 translator(翻译)权限才能利用。

利用条件与风险

利用前提是攻击者已拥有该插件的翻译权限,通常需通过其他方式获取低权限账户。实战中可导致敏感配置文件等信息泄露,为进一步攻击提供条件。

修复建议

升级 Loco Translate 插件至 2.8.9 或更高版本。临时缓解措施:严格限制可授予翻译权限的用户范围,暂无其他公开缓解方案。

原始情报

The Loco Translate WordPress plugin before 2.8.9 does not restrict which file paths its translation file routes will read, allowing users granted the Loco Translate WordPress plugin before 2.8.9’s translator capability to retrieve the contents of files of certain types from anywhere on the server, including outside the web root.