


Perceptive Security
SOC/SIEM Consultancy

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to…
Published:
26 augustus 2026 om 00:00:00
Alert date:
26 augustus 2026 om 19:06:19
Source:
nvd.nist.gov
Web Technologies, Identity & Access
A critical sensitive information exposure vulnerability exists in the TranslatePress WordPress plugin (versions up to and including 3.3.1). Unauthenticated attackers can exploit the 'trp_get_translations_regular' AJAX action to extract plaintext administrator password-reset URLs, including reset keys and login parameters, from the translation dictionary table. This enables full administrator account takeover. The vulnerability is triggered when automatic string saving is enabled (default setting) and the target administrator's profile locale is set to a published secondary language, causing the password-reset URL to be stored as a translatable string. The combination of default settings and unauthenticated access makes this particularly dangerous for WordPress sites using TranslatePress. A patch is available via changeset 3645229 in the plugin repository.
Technical details
Mitigation steps:
Affected products:
TranslatePress WordPress Plugin 3.3.1 and below
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-19632
https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.1/class-translate-press.php#L361
https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.1/class-translate-press.php#L531
https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.1/includes/class-editor-api-regular-strings.php#L35
https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.1/includes/class-editor-api-regular-strings.php#L93
https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.1/includes/class-translation-render.php#L2061
https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.1/includes/class-translation-render.php#L2257
https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.1/includes/class-translation-render.php#L2371
https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.1/includes/queries/class-query.php#L1258
https://plugins.trac.wordpress.org/changeset/3645229/translatepress-multilingual
https://www.wordfence.com/threat-intel/vulnerabilities/id/4f4ebf09-b089-4118-a0ee-399243253f9c?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
