← Terug naar overzicht

CVE-2026-19632 affects the TranslatePress WordPress plugin in all versions up to and including 3.3.1. An unauthenticated attacker can exploit the 'trp_get_translations_regular' AJAX action to extract sensitive information from the translation dictionary table. Specifically, the vulnerability exposes raw administrator password-reset URLs, including plaintext reset keys and login parameters. This exposure enables full administrator account takeover without authentication. The vulnerability is triggered only when automatic string saving is enabled (the default) and the administrator's profile locale is set to a published secondary language. Under these conditions, password-reset URLs are inadvertently stored as translatable strings in the secondary-language dictionary table. Multiple source code references in the plugin's class files have been identified as contributing to the flaw. A patch is available via a plugin changeset, and the issue is documented by both NVD and Wordfence.

Affected products

  • TranslatePress WordPress Plugin (versions up to 3.3.1)

Related CVE's

  • CVE-2026-19632

Categories

  • Identity & Access
  • Web Technologies