Critical WordPress TranslatePress Bug Enables Complete Site Takeover
ID: 96619559-e986-539c-91c3-254b1434205c
STIX ID: report--96619559-e986-539c-91c3-254b1434205c
Feed Name: Cyber Press
### Executive summary A critical vulnerability (CVE-2026-19632, CVSS 9.8) in TranslatePress (<= 3.3.1) allows unauthenticated attackers to extract plaintext password-reset URLs from the plugin's translation dictionary via a public AJAX handler and hijack administrator accounts on affected WordPress sites; the issue affects sites with automatic string saving enabled and admins set to a published secondary language. Cozmoslabs released a patch in version 3.3.2 on August 13, 2026, and site owners are urged to update immediately and apply layered defenses such as two-factor authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
