logo

Critical WordPress Plugin Vulnerabilities Allow Admin Account Takeover

ID: c20c036d-b388-59df-9ec8-2d0c23895283

STIX ID: report--c20c036d-b388-59df-9ec8-2d0c23895283

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

...
...

Two critical WordPress plugin vulnerabilities were disclosed: TranslatePress (CVE-2026-19632, CVSS 9.8) and Pods (CVE-2026-19598, CVSS 9.8). Both allow unauthenticated attackers to take over administrator accounts; TranslatePress reportedly impacts 400,000+ sites and Pods had a public proof-of-concept, so administrators are urged to apply patches immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.