PT-2026-81497 · WordPress · Translatepress

·

CVE-2026-19632

·

Published

2026-08-25

·

Updated

2026-08-31

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TranslatePress versions prior to 3.3.2
Description An unauthenticated attacker can retrieve a plaintext password-reset URL via the trp get translations regular AJAX endpoint, enabling the takeover of any administrator account. This issue affects approximately 400,000 WordPress sites and has been exploited in the wild. The flaw is triggerable when automatic string saving is enabled and an administrator's profile language is set to a published secondary language.
Recommendations Update to version 3.3.2. As a temporary workaround, deactivate the plugin until the update can be applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19632

Affected Products

Translatepress