logo

Critical SQL Injection Vulnerability in GPTranslate Plugin (CVE-2026-49776)

ID: 797eb894-705b-56d7-a9d3-2921c415014c

STIX ID: report--797eb894-705b-56d7-a9d3-2921c415014c

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-06-16

Date Updated: 2026-06-22

...
...

A critical unauthenticated SQL injection (CVE-2026-49776, CVSS 9.3) was found in the GPTranslate WordPress plugin (≤2.32.6) that can allow attackers to run arbitrary SQL queries and potentially expose usernames and password hashes; a patch (2.32.7) is available and administrators are urged to update or remove the plugin and apply WAF mitigations. No public exploitation or proof-of-concept has been observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.