logo

Critical WordPress TranslatePress Flaw Lets Attackers Take Over Admin Accounts

ID: 84d13143-3d85-575b-a257-1af55c83e354

STIX ID: report--84d13143-3d85-575b-a257-1af55c83e354

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

Author: Divya

...
...

A critical vulnerability (CVE-2026-19632, CVSS 9.8) in the TranslatePress WordPress plugin (<= 3.3.1) can cause translated password-reset URLs — including plaintext reset keys — to be stored in language-specific translation dictionaries; an unauthenticated attacker can enumerate those entries via the trp_get_translations_regular AJAX action, retrieve a reset link, and take over administrator accounts. The flaw affects over 400,000 sites under specific conditions (automatic string saving enabled and admin using a published secondary language); TranslatePress 3.3.2 was released to patch the issue and Wordfence issued firewall rules while recommending immediate updates, account reviews, and MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.