Normal view

PSA: Critical (9.8) account takeover in TranslatePress, update to 3.3.2 now

25 August 2026 at 11:37

https://preview.redd.it/mb2hmgs0ujlh1.png?width=2428&format=png&auto=webp&s=a0c69c72cdb3f65e680eaa240bc11eaa863faa80

Heads up if you run TranslatePress (Multilingual): all versions up to 3.3.1 have a critical unauthenticated account takeover vuln (CVE-2026-19632, CVSS 9.8). An attacker can pull the raw admin password-reset URL through an AJAX action and hijack the admin account. Wordfence reported blocking active attacks within 24 hours of disclosure, so it's being exploited in the wild.

You're exposed if automatic string saving is on (the default) and an admin's profile language is set to a published secondary language. Fix is to update to 3.3.2, or deactivate the plugin until you can. Source: Wordfence Intelligence.

submitted by /u/BerqWP
[link] [comments]
❌