logo

Critical SQL Injection Vulnerability in GPTranslate Plugin (CVE-2026-49776)

ID: f5498588-d477-56ef-890e-ae192ae03f2e

STIX ID: report--f5498588-d477-56ef-890e-ae192ae03f2e

Feed Name: ThreatCluster

Threat Score
70/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

...
...

A critical unauthenticated SQL injection (CVE-2026-49776) has been identified in the GPTranslate WordPress plugin (≤2.32.6), allowing attackers to execute arbitrary SQL and potentially expose usernames and password hashes. A patch (2.32.7) is available and users are urged to update immediately or disable/remove the plugin; no public exploitation has been observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.