Critical WordPress TranslatePress Flaw Lets Attackers Take Over Admin Accounts
ID: 84d13143-3d85-575b-a257-1af55c83e354
STIX ID: report--84d13143-3d85-575b-a257-1af55c83e354
Feed Name: GBHackers
A critical vulnerability (CVE-2026-19632, CVSS 9.8) in the TranslatePress WordPress plugin (<= 3.3.1) can cause translated password-reset URLs — including plaintext reset keys — to be stored in language-specific translation dictionaries; an unauthenticated attacker can enumerate those entries via the trp_get_translations_regular AJAX action, retrieve a reset link, and take over administrator accounts. The flaw affects over 400,000 sites under specific conditions (automatic string saving enabled and admin using a published secondary language); TranslatePress 3.3.2 was released to patch the issue and Wordfence issued firewall rules while recommending immediate updates, account reviews, and MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
