DEV Community

Cover image for Critical Account Takeover Flaw in TranslatePress Plugin Affects 400,000 WordPress Sites
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

Critical Account Takeover Flaw in TranslatePress Plugin Affects 400,000 WordPress Sites

Summary

TranslatePress patched a critical vulnerability (CVE-2026-19632) that allows unauthenticated attackers to steal administrator password reset links and take over WordPress sites.

Take Action:

If you use the TranslatePress plugin on your WordPress site, update it to version 3.3.2 ASAP, since older versions let attackers steal admin password reset links and take over the whole site. Also turn on two-factor authentication or passkeys for all admin accounts, and check your user list for any new administrators you didn't create.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)