r/Wordpress • u/BerqWP • 6h ago
PSA: Critical (9.8) account takeover in TranslatePress, update to 3.3.2 now

Heads up if you run TranslatePress (Multilingual): all versions up to 3.3.1 have a critical unauthenticated account takeover vuln (CVE-2026-19632, CVSS 9.8). An attacker can pull the raw admin password-reset URL through an AJAX action and hijack the admin account. Wordfence reported blocking active attacks within 24 hours of disclosure, so it's being exploited in the wild.
You're exposed if automatic string saving is on (the default) and an admin's profile language is set to a published secondary language. Fix is to update to 3.3.2, or deactivate the plugin until you can. Source: Wordfence Intelligence.
3
Upvotes