As cited
Copy frozen at (site build).
vulnerabilities
400,000 WordPress Sites Affected by Account Takeover Vulnerability in TranslatePress WordPress Plugin
An unauthenticated account takeover vulnerability in the TranslatePress WordPress plugin affects approximately 400,000 sites running versions up to 3.3.1. The flaw allows attackers to extract administrator password reset links from the plugin's translation dictionary and gain full site access, but only when an admin's profile language is set to a published secondary language. TranslatePress released patched version 3.3.2 on August 13, 2026, and Wordfence deployed firewall protection for premium users the same day, with free user protection following on September 12, 2026.
Why it matters: WordPress site administrators using TranslatePress must update to version 3.3.2 immediately to prevent account takeover and complete site compromise; CVE-2026-19632 carries a critical 9.8 CVSS score and is listed on the known exploited vulnerabilities catalog.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
400,000 WordPress Sites Affected by Account Takeover Vulnerability in TranslatePress WordPress Plugin
An unauthenticated account takeover vulnerability in the TranslatePress WordPress plugin affects approximately 400,000 sites running versions up to 3.3.1. The flaw allows attackers to extract administrator password reset links from the plugin's translation dictionary and gain full site access, but only when an admin's profile language is set to a published secondary language. TranslatePress released patched version 3.3.2 on August 13, 2026, and Wordfence deployed firewall protection for premium users the same day, with free user protection following on September 12, 2026.
Why it matters: WordPress site administrators using TranslatePress must update to version 3.3.2 immediately to prevent account takeover and complete site compromise; CVE-2026-19632 carries a critical 9.8 CVSS score and is listed on the known exploited vulnerabilities catalog.
- Source published
- First seen by Cybersecurity Tracker