Summary
TranslatePress patched a critical vulnerability (CVE-2026-19632) that allows unauthenticated attackers to steal administrator password reset links and take over WordPress sites.
Take Action:
If you use the TranslatePress plugin on your WordPress site, update it to version 3.3.2 ASAP, since older versions let attackers steal admin password reset links and take over the whole site. Also turn on two-factor authentication or passkeys for all admin accounts, and check your user list for any new administrators you didn't create.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)