Critical SQL Injection Vulnerability in GPTranslate Plugin (CVE-2026-49776)
ID: 797eb894-705b-56d7-a9d3-2921c415014c
STIX ID: report--797eb894-705b-56d7-a9d3-2921c415014c
Feed Name: ThreatCluster
Threat Score
A critical unauthenticated SQL injection (CVE-2026-49776, CVSS 9.3) was found in the GPTranslate WordPress plugin (≤2.32.6) that can allow attackers to run arbitrary SQL queries and potentially expose usernames and password hashes; a patch (2.32.7) is available and administrators are urged to update or remove the plugin and apply WAF mitigations. No public exploitation or proof-of-concept has been observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
