Cyber Security News

WordPress Plugin Vulnerability Exposes 400,000 Sites to Account Takeover Attacks

A critical vulnerability in the TranslatePress WordPress plugin could allow unauthenticated attackers to hijack administrator accounts and fully compromise affected websites.

The flaw, tracked as CVE-2026-19632, affects TranslatePress versions up to 3.3.1 and has been fixed in version 3.3.2. TranslatePress is a multilingual WordPress plugin with more than 400,000 active installations.

Wordfence assigned the vulnerability a CVSS score of 9.8, classifying it as critical. Security researcher momopon1415 responsibly reported the issue through the Wordfence Bug Bounty Program and received a $975 reward.

The vulnerability stems from the way TranslatePress processes password reset emails and saves translatable strings. The plugin can translate outgoing WordPress emails by intercepting the wp_mail() function.

When an administrator requests a password reset, WordPress generates an email containing a reset URL with a plaintext reset key and login parameters.

Under specific conditions, TranslatePress stores this sensitive reset URL in a secondary-language translation dictionary table. Automatic string saving must be enabled, which is the default setting.

In addition, the targeted administrator’s profile language must be configured to use a published secondary language rather than the website’s default language.

Researchers found that attackers could retrieve these saved dictionary entries through the plugin’s publicly accessible trp_get_translations_regular AJAX action.

The endpoint accepts attacker-supplied string identifiers and returns matching translation records. This could enable an unauthenticated attacker to enumerate translation data and locate a stored password reset URL.

TranslatePress WordPress Plugin Vulnerability

An attacker who knows an administrator’s username or email address could trigger a password reset request, extract the exposed reset link from the translation dictionary, set a new password, and log in as the administrator. Successful exploitation would give the attacker complete control over the WordPress site.

With administrator access, threat actors could create new privileged accounts, install malicious plugins or backdoored themes, alter website content, steal sensitive information, or use the compromised site to distribute malware.

Wordfence Firewall (Source: Wordfence)

The issue therefore poses a serious risk to businesses, publishers, e-commerce stores, and organizations that use TranslatePress.
The flaw does not affect every TranslatePress deployment in the same way.

The password reset URL is only exposed when the targeted administrator uses a published secondary-language profile locale. Administrators whose accounts use the site’s default language do not have their password reset emails processed through the affected secondary-language translation workflow.

Wordfence received the report on August 11, 2026, disclosed the issue to TranslatePress developer Cozmoslabs on August 12, and confirmed that the vendor released TranslatePress version 3.3.2 on August 13.

Site owners should immediately update TranslatePress to version 3.3.2 or later. Administrators should also enable two-factor authentication or passkeys, limit administrator accounts, review user activity, and inspect installed plugins and themes for unauthorized changes.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago