A critical unauthenticated privilege escalation vulnerability has been identified in the TranslatePress WordPress plugin affecting versions 3.3.2 and earlier. The vulnerability allows unauthenticated attackers to escalate their privileges without requiring any authentication. This poses a significant security risk to WordPress sites using the affected plugin versions. The vulnerability has been assigned CVE-2026-78267 and is tracked by both NVD and Patchstack. Website administrators using TranslatePress are strongly advised to update to a patched version immediately to mitigate the risk of exploitation.