CVE-2026-19632 (matched: wordpress)

  • Wednesday, 26th August, 2026
  • 16:06pm

A security flaw has been identified in the TranslatePress multilingual plugin for WordPress, a popular tool used to build and manage websites that support multiple languages. The issue affects all versions of the plugin up to and including 3.3.1.

The flaw can expose sensitive administrator account information if two common default conditions are met: the plugin’s automatic string saving feature is enabled (this is the default setting) and your WordPress admin profile is set to a published secondary language on your site. In these cases, unauthenticated third parties could access raw password reset links for admin accounts, including the secret one-time reset keys, which would allow them to take full control of your site’s administrator account.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-19632

« Back