Home ยท Wiki ยท Vulnerabilities & CVEs
type: vulnerability ยท created: 2026-08-30 ยท updated: 2026-08-30 ยท tags: [cve, wordpress, translatepress, plugin, password-reset, information-exposure, critical] ยท confidence: high ยท severity: critical ยท affected_sectors: [Global (Macro)] ยท au_impact: false

CVE-2026-19632

CVE-2026-19632 is a critical vulnerability (CVSS 9.8) in the TranslatePress WordPress plugin. The flaw exposes raw administrator password-reset URLs to unauthenticated attackers, allowing an attacker to reset an administrator password and take over the site's administrative account.

Disclosed by Wordfence and Patchstack on 29 August 2026 among five critical WordPress plugin and theme flaws, TranslatePress is a widely used multilingual plugin, so the exposure potentially affects millions of WordPress sites. No in-the-wild exploitation had been disclosed at publication, but the direct path to administrator credentials warrants immediate patching.

Source