TranslatePress Flaw (CVE-2026-19632) Exposes 400,000 WordPress Sites to Account Takeover
ID: 879c0607-fba4-5bb9-b322-19b25a0c5f57
STIX ID: report--879c0607-fba4-5bb9-b322-19b25a0c5f57
Feed Name: securityonline.info
Threat Score
A critical TranslatePress vulnerability (CVE-2026-19632) allows unauthenticated attackers to read administrator password-reset URLs from stored translation strings via a public AJAX endpoint, enabling full admin account takeover; it affects TranslatePress versions up to 3.3.1 and is fixed in 3.3.2 — patch immediately or review admin locale settings and monitor for unexpected reset requests.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
