CRITICAL 9.8 CVE-2026-19632 Published 26 Aug 2026

WordPress TranslatePress Plugin Sensitive Info Exposure

Worried this affects one of your servers?

The TranslatePress plugin for WordPress is vulnerable to Sensitive Information Exposure.

TranslatePress stores administrator password-reset URLs in a translatable string table, allowing unauthenticated attackers to extract them and take over administrator accounts.

This vulnerability is exploitable when automatic string saving is enabled and the administrator's profile locale is set to a published secondary language.

Reference: CVE-2026-19632 on NVD

← Back to Security News