CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

400,000 WordPress Sites Affected by Account Takeover Vulnerability in TranslatePress WordPress Plugin

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5815

As cited

Copy frozen at (site build).

vulnerabilities

400,000 WordPress Sites Affected by Account Takeover Vulnerability in TranslatePress WordPress Plugin

An unauthenticated account takeover vulnerability in the TranslatePress WordPress plugin affects approximately 400,000 sites running versions up to 3.3.1. The flaw allows attackers to extract administrator password reset links from the plugin's translation dictionary and gain full site access, but only when an admin's profile language is set to a published secondary language. TranslatePress released patched version 3.3.2 on August 13, 2026, and Wordfence deployed firewall protection for premium users the same day, with free user protection following on September 12, 2026.

Why it matters: WordPress site administrators using TranslatePress must update to version 3.3.2 immediately to prevent account takeover and complete site compromise; CVE-2026-19632 carries a critical 9.8 CVSS score and is listed on the known exploited vulnerabilities catalog.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

400,000 WordPress Sites Affected by Account Takeover Vulnerability in TranslatePress WordPress Plugin

An unauthenticated account takeover vulnerability in the TranslatePress WordPress plugin affects approximately 400,000 sites running versions up to 3.3.1. The flaw allows attackers to extract administrator password reset links from the plugin's translation dictionary and gain full site access, but only when an admin's profile language is set to a published secondary language. TranslatePress released patched version 3.3.2 on August 13, 2026, and Wordfence deployed firewall protection for premium users the same day, with free user protection following on September 12, 2026.

Why it matters: WordPress site administrators using TranslatePress must update to version 3.3.2 immediately to prevent account takeover and complete site compromise; CVE-2026-19632 carries a critical 9.8 CVSS score and is listed on the known exploited vulnerabilities catalog.

VendorsWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary