A critical security vulnerability (CVE-2026-19632) in the TranslatePress plugin affects versions up to 3.3.1, allowing unauthorized attackers to steal an administrator's password reset link and gain full control of the site. This flaw has a CVSS score of 9.8 and impacts over 400,000 installations. It arises from the plugin's mishandling of email translations and public AJAX actions, exposing sensitive information. Users are advised to update to version 3.3.2 to mitigate this risk.
CVE-2026-19632 bug in TranslatePress threatens WordPress sites
CyberSIXT Evidence Panel
Article by CyberSIXT