wordpress cve-2026-19632 translatepress

TranslatePress Flaw CVE-2026-19632 Risks 400k Sites

A critical security vulnerability tracked as CVE-2026-19632 has been discovered in TranslatePress, a highly popular WordPress translation plugin. With a near-perfect CVSS score of 9.8, this flaw allows unauthenticated attackers to completely seize administrator accounts.

Because the bug requires no login privileges or advanced technical skills to exploit, the scale of exposure is massive. It threatens more than 400,000 active WordPress installations globally.

If your website uses TranslatePress to manage multilingual content, understanding how this flaw works and applying the immediate fix is vital to keeping your digital assets safe.

Quick Summary

  • Vulnerability ID: CVE-2026-19632
  • Severity Score: 9.8 Critical (CVSS v3.1)
  • Vulnerability Type: Information Disclosure / Authentication Bypass via Database Leak
  • Affected Versions: All versions up to and including 3.3.1
  • Patched Version: TranslatePress 3.3.2 (Released August 13, 2026)
  • Impact: Full unauthenticated administrator account takeover

Why the TranslatePress Account Takeover Flaw Matters

The TranslatePress account takeover vulnerability is uniquely dangerous due to its zero-click, unauthenticated nature. Security data from Wordfence highlights that any anonymous visitor can theoretically trigger this exploit.

A single unauthorized request can hand full control of your WordPress site to a complete stranger. Once an attacker gains administrator access, they own everything. They can inject malicious scripts, steal customer data, deface the website, or completely lock out the rightful owners.

Fortunately, security researcher momopon1415 discovered and responsibly reported the issue through the Wordfence Bug Bounty Program, preventing widespread zero-day damage before a patch could be engineered.

Technical Breakdown, How the Attack Works

The root cause of CVE-2026-19632 lies in a dangerous interaction between two seemingly standard plugin features: email translation hooks and public AJAX actions.

1. Email Translation Interception

TranslatePress hooks into the WordPress core mail engine using the wp_mail_filter() function to translate outgoing emails. To build its translation database efficiently, the plugin logs translatable strings directly into per-language dictionary tables.

When a site administrator requests a password reset, WordPress generates a unique, plaintext reset key embedded in a URL. If the administrator’s profile locale is set to a published secondary language, TranslatePress treats this automated email as content to be translated. Because the “automatic string saving” feature is enabled by default, the entire password reset URL—including the active plaintext reset key—is saved into a publicly accessible database table.

2. Public AJAX Access

The second half of the vulnerability involves a public-facing AJAX action called trp_get_translations_regular. This action is designed to fetch translated strings for visitors. However, because it lacked proper authorization checks, it allows any unauthenticated user to query the dictionary rows.

An attacker can simply:

  1. Go to the standard WordPress login screen and request a password reset for the administrator’s username.
  2. Send a query via the public AJAX endpoint to fetch recent entries from the translation dictionary tables.
  3. Extract the raw, plaintext administrator password-reset URL directly from the database response and take over the account.

Current Exploitation Status

As of today, no exploitation in the wild has been confirmed. Additionally, no public proof-of-concept (PoC) code has been released to the public.

However, because the attack mechanism relies on standard plugin functions and requires low technical complexity, security analysts warn that automated scanning tools will likely target unpatched sites soon. Immediate patching is your best line of defense.

Is Your WordPress Site Vulnerable?

Your website is at risk if it meets the following criteria:

  • Plugin Slug: The site runs the translatepress-multilingual plugin.
  • Active Version: The installed version is 3.3.1 or lower.
  • Default Settings: The “automatic string saving” feature is turned on (default behavior).
  • Admin Language: A target administrator account uses a published secondary language as their profile locale.

How to Fix and Mitigate CVE-2026-19632

Step 1: Update TranslatePress Immediately

The definitive solution is to update the plugin to version 3.3.2 or higher. Cozmoslabs, the development team behind TranslatePress, released the security fix on August 13, 2026, on the exact same day the vulnerability report was validated.

Step 2: Temporary Workarounds (If You Cannot Patch)

If an immediate update is impossible due to development freezes or compatibility testing, take these protective steps right away:

  • Check Administrator Profiles: Ensure all user accounts with administrator privileges have their profile language set to the site’s primary/default language. Avoid setting admin profiles to secondary languages.
  • Monitor Email Activity: Keep a close eye on your site’s audit logs for any unexpected password reset requests that you or your team did not initiate.
  • Disable Automatic String Saving: Turn off automatic string logging within the TranslatePress settings menu temporarily to stop data from caching to the database tables.

FREQUENTLY ASKED QUESTIONS (FAQ)

What is CVE-2026-19632?

CVE-2026-19632 is a critical security flaw in the TranslatePress WordPress plugin that allows unauthenticated individuals to steal administrator password reset links from the database and take over accounts.

How does the TranslatePress account takeover happen?

The plugin saves password reset links into public translation tables when an admin uses a secondary language. Attackers can then pull these links out using a public AJAX action without logging in.

Which versions of TranslatePress are safe?

TranslatePress version 3.3.2 and all subsequent releases contain the patch and are safe from this specific database exposure vulnerability.

Has this TranslatePress bug been used by hackers yet?

There is currently no evidence that hackers have exploited CVE-2026-19632 in the wild, but web admins should update quickly before automated exploit tools are developed.

What should I do if I see an unexpected password reset email?

If you receive a password reset email you didn’t ask for, it could mean someone is trying to exploit your site. Do not click the link, update your plugins immediately, and check your security logs.

Read more CVE , find out and visit my website (Nomatali). Thank you.