A critical vulnerability in the TranslatePress WordPress plugin could allow unauthenticated attackers to hijack administrator accounts and fully compromise affected websites.
The flaw, tracked as CVE-2026-19632, affects TranslatePress versions up to 3.3.1 and has been fixed in version 3.3.2. TranslatePress is a multilingual WordPress plugin with more than 400,000 active installations.
Wordfence assigned the vulnerability a CVSS score of 9.8, classifying it as critical. Security researcher momopon1415 responsibly reported the issue through the Wordfence Bug Bounty Program and received a $975 reward.
The vulnerability stems from the way TranslatePress processes password reset emails and saves translatable strings. The plugin can translate outgoing WordPress emails by intercepting the wp_mail() function.
When an administrator requests a password reset, WordPress generates an email containing a reset URL with a plaintext reset key and login parameters.
Under specific conditions, TranslatePress stores this sensitive reset URL in a secondary-language translation dictionary table. Automatic string saving must be enabled, which is the default setting.
In addition, the targeted administrator’s profile language must be configured to use a published secondary language rather than the website’s default language.
Researchers found that attackers could retrieve these saved dictionary entries through the plugin’s publicly accessible trp_get_translations_regular AJAX action.
The endpoint accepts attacker-supplied string identifiers and returns matching translation records. This could enable an unauthenticated attacker to enumerate translation data and locate a stored password reset URL.
An attacker who knows an administrator’s username or email address could trigger a password reset request, extract the exposed reset link from the translation dictionary, set a new password, and log in as the administrator. Successful exploitation would give the attacker complete control over the WordPress site.
With administrator access, threat actors could create new privileged accounts, install malicious plugins or backdoored themes, alter website content, steal sensitive information, or use the compromised site to distribute malware.
The issue therefore poses a serious risk to businesses, publishers, e-commerce stores, and organizations that use TranslatePress.
The flaw does not affect every TranslatePress deployment in the same way.
The password reset URL is only exposed when the targeted administrator uses a published secondary-language profile locale. Administrators whose accounts use the site’s default language do not have their password reset emails processed through the affected secondary-language translation workflow.
Wordfence received the report on August 11, 2026, disclosed the issue to TranslatePress developer Cozmoslabs on August 12, and confirmed that the vendor released TranslatePress version 3.3.2 on August 13.
Site owners should immediately update TranslatePress to version 3.3.2 or later. Administrators should also enable two-factor authentication or passkeys, limit administrator accounts, review user activity, and inspect installed plugins and themes for unauthorized changes.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…