logo

TranslatePress Flaw (CVE-2026-19632) Exposes 400,000 WordPress Sites to Account Takeover

ID: 879c0607-fba4-5bb9-b322-19b25a0c5f57

STIX ID: report--879c0607-fba4-5bb9-b322-19b25a0c5f57

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-08-25

Date Updated: 2026-08-26

Author: Do Son

...
...

A critical TranslatePress vulnerability (CVE-2026-19632) allows unauthenticated attackers to read administrator password-reset URLs from stored translation strings via a public AJAX endpoint, enabling full admin account takeover; it affects TranslatePress versions up to 3.3.1 and is fixed in 3.3.2 — patch immediately or review admin locale settings and monitor for unexpected reset requests.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.