Netlas.io[verified]@Netlas_ioDisclosure
The post announces a newly disclosed TranslatePress WordPress plugin flaw that lets attackers steal admin credentials via reset links, enabling full site takeover; no exploit code, patch details, or active use evidence is provided.
dbugs[verified]@ptdbugsPoC
A publicly available PoC and exploit code for CVE‑2026‑19632 enable unauthenticated attackers to retrieve password‑reset URLs and take over administrators in the TranslatePress WordPress plugin. No active exploitation is reported.
Rıdvan Yağlı[verified]@ridvanyagliPatch
A critical CVE in TranslatePress permits admin takeover via captured reset links; the vendor advises updating the plugin to remediate the vulnerability.
DFIR Radar[verified]@DFIR_RadarDisclosure
The tweet announces CVE‑2026‑19632, describing how unauthenticated attackers can recover a password‑reset URL in TranslatePress <=3.3.1 and take over any admin account, and urges users to update to 3.3.2.
yousukezan[verified]@yousukezanDisclosure
A critical, unauthenticated vulnerability (CVE‑2026‑19632) in TranslatePress allows attackers to retrieve password reset links and takeover accounts; the issue is disclosed, details are provided, and a 3.3.2 patch has been released.
The Daily Tech Feed[verified]@dailytechonxPatch
Critical TranslatePress vulnerability CVE-2026-19632 enables account hijacking through exposed password reset URLs; over 400k sites must be updated to v3.3.2 immediately.
CyberSignal | Cybersecurity News[verified]@XQOPTRXPatch
A critical TranslatePress flaw allows attackers to obtain admin reset URLs via the translation dictionary; the vendor released a patch (3.3.2), but no evidence of active exploitation is reported.
Rıdvan Yağlı[verified]@ridvanyagliPoC
A publicly available PoC for the TranslatePress unauthenticated account takeover vulnerability (CVE‑2026‑19632) is shared on GitHub.