CVE-2026-19632Disclosure

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 7 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it possible for unauthenticated attackers to extract the raw administrator password-reset URL — including the plaintext reset key and login parameters stored in the translation dictionary table — enabling full administrator account takeover. This vulnerability is only exploitable when automatic string saving is enabled (the default setting) and the target administrator's profile locale is set to a published secondary language, as these conditions cause the password-reset URL to be persisted as a translatable string in the secondary-language dictionary table.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-640

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 19 mentions across 8 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 15 signals
  • Disclosure: 8 classified signals
  • General: 2 classified signals
  • Peaked 6d ago at 7 mentions (2026-08-26); latest day: 1
  • 19 total mentions across 8 days

Deep dive

Activity timeline19 mentions / 8d
02457Mentions · 2026-08-25: 3Mentions · 2026-08-26: 7Mentions · 2026-08-27: 1Mentions · 2026-08-28: 3Mentions · 2026-08-29: 1Mentions · 2026-08-31: 1Mentions · 2026-09-03: 2Mentions · 2026-09-09: 1PoC Mentioned / Linked · 2026-08-28: 2Exploit Tool / Code · 2026-08-28: 2Active Exploitation · 2026-08-25: 1Patch / Workaround · 2026-08-25: 3Patch / Workaround · 2026-08-26: 4Patch / Workaround · 2026-09-03: 2Technical Details · 2026-08-25: 3Technical Details · 2026-08-26: 6Technical Details · 2026-08-28: 3Technical Details · 2026-08-29: 1Technical Details · 2026-09-03: 1Technical Details · 2026-09-09: 108-2508-2608-2708-2808-2908-3109-0309-09
Signal classification5 categories
Disclosure
842.1%
Patch
631.6%
General
210.5%
PoC
210.5%
Active Exploitation
15.3%
Referenced assets19 URLs
Classification over time
DateTotalLabels
2026-08-253
Active Exploitation1Disclosure2
2026-08-267
Disclosure3Patch4
2026-08-271
General1
2026-08-283
Disclosure1PoC2
2026-08-291
Disclosure1
2026-08-311
General1
2026-09-032
Patch2
2026-09-091
Disclosure1
Full discourse19 posts
  • elhacker.NET@elhackernet
    General

    Vulnerabilidad en plugin TranslatePress de WordPress expone 400.000 sitios a robo de cuentas Se ha detectado una vulnerabilidad crítica (CVE-2026-19632) en el plugin de WordPress TranslatePress https://blog.elhacker.net/2026/08/vulnerabilidad-en-plugin-translatepress.html

    Post summary

    The post alerts to a critical CVE in the TranslatePress plugin but provides no actionable details, evidence of exploitation, or mitigation guidance.

    01322165.6K
    142.4K followersView on X
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-19632: Account takeover vulnerability in TranslatePress WordPress plugin, 9.8 rating ‍🔥 A recently disclosed vulnerability in the TranslatePress WordPress plugin allows unauthenticated attackers to extract an administrator’s password reset link, reset the account’s password, and log in as that administrator, leading to complete site takeover. 👉 https://nt.ls/oe1hr

    Post summary

    The post announces a newly disclosed TranslatePress WordPress plugin flaw that lets attackers steal admin credentials via reset links, enabling full site takeover; no exploit code, patch details, or active use evidence is provided.

    0201581.2K
    7.7K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-19632 Vendor: WordPress / cozmoslabs Product: TranslatePress – Translate Multilingual sites with AI Translation (WordPress plugin) Description: The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it possible for unauthenticated attackers to extract the raw administrator password-reset URL — including the plaintext reset key and login parameters stored in the translation dictionary table — enabling full administrator account takeover. This vulnerability is only exploitable when automatic string saving is enabled (the default setting) and the target administrator's profile locale is set to a published secondary language, as these conditions cause the password-reset URL to be persisted as a translatable string in the secondary-language dictionary table. Link: • https://github.com/DeadExpl0it/CVE-2026-19632-POC • https://github.com/yonliud/cve-2026-19632 #dbugs_vuln

    Post summary

    A publicly available PoC and exploit code for CVE‑2026‑19632 enable unauthenticated attackers to retrieve password‑reset URLs and take over administrators in the TranslatePress WordPress plugin. No active exploitation is reported.

    0201481.2K
    3.6K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-19632 - critical 🚨 TranslatePress <= 3.3.1 - Unauthenticated Account Takeover > TranslatePress WordPress plugin <= 3.3.1 contains a sensitive information exposure ca... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-19632 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces CVE‑2026‑19632 for TranslatePress <=3.3.1, noting unauthenticated account takeover due to sensitive data exposure, without any mention of active exploitation or remediation.

    03060354
    1.3K followersView on X
  • 宏福商事-KOFUKU(公式)@kofukutrading
    Disclosure

    WordPress 40万サイトに緊急警告 TranslatePressで「ログイン不要」の管理者乗っ取り級脆弱性 https://kofukutrading.com/translatepress-wordpress-account-takeover-cve-2026-19632/ https://t.co/aaASgckQ3H

    Post summary

    An emergency warning is issued for WordPress plugin TranslatePress, indicating a critical admin takeover vulnerability (CVE-2026-19632) with no details about PoC, exploitation, or fixes.

    04050287
    8.5K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Patch

    🔴 WordPress'te TranslatePress eklentisindeki CVE-2026-19632 açığı, saldırganların admin hesaplarının şifre sıfırlama bağlantılarını ele geçirerek yönetici hesaplarını ele geçirmesine izin veriyor. Bu açık 400,000 siteyi etkiliyor. 🔴 CVSS: 9.8/10 🌐 400.000+ aktif kurulum etkileniyor ⚠️ Etkilenen sürümler: 3.3.1 ve öncesi ✅ Çözüm: TranslatePress'i güncelleyin. Açık, şifre sıfırlama bağlantısındaki token'ın TranslatePress'in çeviri veritabanına kaydedilmesi ve dışarıdan erişilebilir olması nedeniyle ortaya çıkıyor.

    Post summary

    A critical CVE in TranslatePress permits admin takeover via captured reset links; the vendor advises updating the plugin to remediate the vulnerability.

    00151541
    2.4K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Active Exploitation

    A critical TranslatePress vulnerability (CVE-2026-19632) lets attackers steal admin reset links and take over 400,000 WordPress sites. Update to 3.3.2 now. #WordPress #TranslatePress #CyberSecurity #CVE202619632 #WebSecurity https://securityonline.info/translatepress-account-takeover-vulnerability/

    Post summary

    TranslatePress CVE-2026-19632 is actively exploited, enabling attackers to hijack admin reset links and compromise over 400,000 WordPress sites, and users are urged to update to version 3.3.2.

    11040466
    13.0K followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    CVE-2026-19632 (CVSS 9.8) in TranslatePress &lt;= 3.3.1 lets unauthenticated attackers pull a plaintext password-reset URL from the trp_get_translations_regular AJAX endpoint, then take over any admin account. Update to 3.3.2 now. #DFIR_Radar https://t.co/gMyPXETZrI

    Post summary

    The tweet announces CVE‑2026‑19632, describing how unauthenticated attackers can recover a password‑reset URL in TranslatePress <=3.3.1 and take over any admin account, and urges users to update to 3.3.2.

    10031361
    2.0K followersView on X
  • yousukezan@yousukezan
    Disclosure

    WordPress向け翻訳プラグイン「TranslatePress」に、認証なしの攻撃者が管理者のパスワード再設定リンクを取得し、アカウントを乗っ取れる重大な脆弱性「CVE-2026-19632」が見つかった。影響は3.3.1以下で、3.3.2で修正された。 問題は、TranslatePressが送信メールの翻訳対象文字列を言語別の辞書テーブルへ保存する仕組みと、公開AJAXアクションtrp_get_translations_regularの組み合わせで生じる。管理者のロケールが第2言語で、自動文字列保存が有効な場合、パスワード再設定メール内の平文リセットキーを含むURLが辞書へ保存される。攻撃者はパスワード再設定を発生させた後、認証なしで公開AJAXからURLを取得できるという。Wordfenceによると、TranslatePressは40万以上のサイトで有効化されている。悪用には自動文字列保存が有効で、対象管理者のロケールが公開済みの第2言語である必要がある。実際の悪用や公開PoCは確認されていない。Cozmoslabsは2026年8月13日に報告を確認し、同日3.3.2を公開した。 https://securityonline.info/translatepress-account-takeover-vulnerability/

    Post summary

    A critical, unauthenticated vulnerability (CVE‑2026‑19632) in TranslatePress allows attackers to retrieve password reset links and takeover accounts; the issue is disclosed, details are provided, and a 3.3.2 patch has been released.

    000311.4K
    16.0K followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    A critical TranslatePress vulnerability (CVE-2026-19632) in versions up to 3.3.1 allows unauthenticated attackers to hijack WordPress admin accounts by exposing password reset URLs via translations. Over 400,000 sites are affected. Update to version 3.3.2 NOW. Key steps: enable two-factor or passkeys, limit admin accounts, audit plugins and themes. The risk is real; patching is urgent. #WordPress #TranslatePress #Vulnerability #WebSecurity #PluginBug #CVE2026 https://thedailytechfeed.com/critical-translatepress-bug-lets-hackers-take-over-400000-wordpress-sites/

    Post summary

    Critical TranslatePress vulnerability CVE-2026-19632 enables account hijacking through exposed password reset URLs; over 400k sites must be updated to v3.3.2 immediately.

    0110078
    663 followersView on X
  • iototsecnews@iototsecnews
    Patch

    WordPress TranslatePress の脆弱性 CVE-2026-19632 が FIX:管理者アカウント乗っ取りの恐れ https://iototsecnews.jp/2026/08/26/critical-wordpress-translatepress-flaw-lets-attackers-take-over-admin-accounts/ WordPress 向けプラグイン TranslatePress に深刻な脆弱性 CVE-2026-19632 が発見されました。特定の条件下での翻訳処理により、データベース内にパスワード・リセット URL が保存され、未認証の攻撃者に取得される恐れがあります。この問題を悪用する攻撃者は、パスワードのリセット/不正なログイン/管理者権限の乗っ取り/Web サイトの完全な侵害といった深刻な影響を引き起こす可能性があります。安全な運用のために、該当プラグインをバージョン 3.3.2 以降へ速やかにアップデートすることや、管理者アカウントの不審な変更の確認、多要素認証の有効化などの対策が求められます。 #CVE202619632 #TranslatePress #Vulnerability #WordPress

    Post summary

    The advisory announces CVE‑2026‑19632 affecting WordPress TranslatePress, explaining how attackers can retrieve reset URLs and hijack admin accounts, and urges users to update to v3.3.2 or later and enable multi‑factor authentication for protection.

    00010176
    510 followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Patch

    🚨 Critical TranslatePress Flaw Could Expose WordPress Admin Reset Links — 400,000+ Installations CyberSignal Priority: 🔴 VERY HIGH Source: Cyber Security News Date: August 26, 2026 Category: Vulnerability · WordPress · Account Takeover CVE: CVE-2026-19632 CVSS: 9.8 A critical vulnerability has been disclosed in TranslatePress, a multilingual WordPress plugin with more than 400,000 active installations. The flaw could allow an unauthenticated attacker to obtain an administrator's password-reset URL and potentially take control of the WordPress site. 🔎 How the vulnerability works When an administrator requests a password reset, WordPress generates an email containing: a reset URL ↓ plaintext reset key ↓ login parameters. TranslatePress can intercept outgoing WordPress emails so their text can be translated. Under vulnerable conditions, the plugin stores the password-reset URL inside a secondary-language translation dictionary. Attackers can then query the publicly accessible: trp_get_translations_regular AJAX action and attempt to retrieve the stored translation record containing the reset URL. Possible attack chain: know administrator username/email ↓ trigger password-reset request ↓ reset URL enters translation dictionary ↓ unauthenticated AJAX request retrieves translation data ↓ attacker obtains reset URL ↓ administrator password changed ↓ WordPress administrator account compromised. ⚠️ Important condition This does not mean every one of the 400,000 installations is directly exploitable. The vulnerable scenario requires conditions including: automatic string saving being enabled — the default and: the targeted administrator using a published secondary language instead of the site's default language. 🛠️ Fix Affected: TranslatePress ≤ 3.3.1 Fixed: TranslatePress 3.3.2 The vendor released the patched version on August 13. 🧠 Why it matters Successful administrator takeover could allow attackers to: create privileged accounts install malicious plugins install backdoored themes modify website content steal information or use the compromised WordPress site to distribute malware. Organizations using TranslatePress should update immediately and review administrator activity for unauthorized changes. 🔗 Source: Cyber Security News

    Post summary

    A critical TranslatePress flaw allows attackers to obtain admin reset URLs via the translation dictionary; the vendor released a patch (3.3.2), but no evidence of active exploitation is reported.

    0100099
    126 followersView on X
  • Phil_Taboada@Phil24275443
    Patch

    Si tu WordPress es bilingüe con TranslatePress, actualiza a 3.3.4. Si no, pueden tomar la cuenta admin. Sitio de un solo idioma sin el plugin: no te pega. https://www.wavys-technologies.com/es/blog/translatepress-cve-2026-19632

    Post summary

    The post advises bilingual WordPress sites using TranslatePress to update to version 3.3.4 to prevent potential admin takeover, but does not provide PoC, exploit, or technical details.

    0000028
    3 followersView on X
  • SecAlerts@SecAlertsCo
    General

    Vulns in WordPress plugins and themes. CVE-2026-82222, CVSS 10 - https://secalerts.co/vulnerability/CVE-2026-82222 CVE-2026-76581 - https://secalerts.co/vulnerability/CVE-2026-76581 CVE-2026-18431 - https://secalerts.co/vulnerability/CVE-2026-18431 CVE-2026-19632 - https://secalerts.co/vulnerability/CVE-2026-19632 CVE-2026-19598 - https://secalerts.co/vulnerability/CVE-2026-19598 #ciso #cio #cto #msp #mssp https://t.co/ILSfPKqogV

    Post summary

    The tweet lists several WordPress CVEs with links but offers no exploit details, patches, or evidence of active exploitation.

    00000166
    885 followersView on X
  • CVETodo@CveTodo
    Disclosure

    A critical vulnerability in the TranslatePress WordPress plugin — installed on more than 400,000 sites — allows unauthenticated attackers to retrieve an administrator's plaintext password-reset... https://cvetodo.com/news/cve-2026-19632-critical-translatepress-flaw-exposes-admin-password-reset-keys-on-400000-wordpress-si #WordPress #XSS #CriticalVulnerability #CVE #InfoSec https://t.co/RccugrSFiz

    Post summary

    The tweet announces a critical vulnerability in the TranslatePress WordPress plugin that allows unauthenticated attackers to retrieve administrators’ plaintext password‑reset keys on more than 400,000 sites.

    0000068
    19 followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    CVE-2026-19632 — TranslatePress Unauthenticated Account Takeover PoC: https://github.com/DeadExpl0it/CVE-2026-19632-POC

    Post summary

    A publicly available PoC for the TranslatePress unauthenticated account takeover vulnerability (CVE‑2026‑19632) is shared on GitHub.

    00000213
    2.1K followersView on X
  • Cybersecurity News DE@cybsecuritynews
    Disclosure

    #schwachstellen TranslatePress-CVE 2026-19632 erlaubt Admin-Übernahme in WordPress #cve202619632 #translatepress #wordpress https://cybersecurity-news.de/translatepress-cve-2026-19632-admin-uebernahme-wordpress

    Post summary

    The tweet announces CVE-2026-19632 in TranslatePress, stating it enables admin takeover in WordPress. Further details would be in the linked article.

    0000035
    10 followersView on X
  • Ian Bishop@ianbishop2021
    Patch

    Critical flaw in TranslatePress (CVE-2026-19632, CVSS 9.8) lets unauthenticated attackers grab admin password reset links via a public AJAX endpoint, exposing 400,000+ WordPress sites to takeover. Patched in v3.3.2 — update now. #WordPress https://cybersecuritynews.com/translatepress-wordpress-plugin-vulnerability/?utm_source=secnewsheadlines.com&utm_medium=social&utm_campaign=x

    Post summary

    A critical TranslatePress flaw (CVE-2026-19632) allows attackers to retrieve admin password reset links; the issue is fixed in v3.3.2 and users are urged to update immediately.

    00000184
    123 followersView on X
  • LoreleiWeb@LoreleiWeb
    Disclosure

    🆕👉 TranslatePress https://wpdeeply.com/translatepress-3-3-1-unauthenticated-account-takeover-password-reset-link-disclosure/ #loreleiweb Wordfence published CVE-2026-19632 on August 25, 2026 for TranslatePress – Translate Multilingual sites with AI Translation, a WordPress plugin with 400,000+ active installations. The flaw can let unauthenticated attacke… https://t.co/ydFeu2xO40

    Post summary

    Wordfence announced CVE-2026-19632 for TranslatePress, stating the flaw can lead to unauthenticated account takeover via password reset link disclosure; no PoC, exploit, or patch details are provided.

    00000244
    85.9K followersView on X

Explore more