A critical sensitive information exposure vulnerability exists in the TranslatePress WordPress plugin (versions up to and including 3.3.1). Unauthenticated attackers can exploit the 'trp_get_translations_regular' AJAX action to extract plaintext administrator password-reset URLs, including reset keys and login parameters, from the translation dictionary table. This enables full administrator account takeover. The vulnerability is triggered when automatic string saving is enabled (default setting) and the target administrator's profile locale is set to a published secondary language, causing the password-reset URL to be stored as a translatable string. The combination of default settings and unauthenticated access makes this particularly dangerous for WordPress sites using TranslatePress. A patch is available via changeset 3645229 in the plugin repository.