Critical SQL Injection Vulnerability in GPTranslate Plugin (CVE-2026-49776)
ID: f5498588-d477-56ef-890e-ae192ae03f2e
STIX ID: report--f5498588-d477-56ef-890e-ae192ae03f2e
Feed Name: ThreatCluster
Threat Score
A critical unauthenticated SQL injection (CVE-2026-49776) has been identified in the GPTranslate WordPress plugin (≤2.32.6), allowing attackers to execute arbitrary SQL and potentially expose usernames and password hashes. A patch (2.32.7) is available and users are urged to update immediately or disable/remove the plugin; no public exploitation has been observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
