CVE-2026-19632
Received Received - Intake

Sensitive Information Exposure in TranslatePress WordPress Plugin

Vulnerability report for CVE-2026-19632, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-08-26

Assigner: Wordfence

Description

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it possible for unauthenticated attackers to extract the raw administrator password-reset URL β€” including the plaintext reset key and login parameters stored in the translation dictionary table β€” enabling full administrator account takeover. This vulnerability is only exploitable when automatic string saving is enabled (the default setting) and the target administrator's profile locale is set to a published secondary language, as these conditions cause the password-reset URL to be persisted as a translatable string in the secondary-language dictionary table.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-08-26
Generated
2026-08-26
AI Q&A
2026-08-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
translatepress translate_multilingual_sites_with_ai_translation to 3.3.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-640 The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the TranslatePress WordPress plugin allows unauthenticated attackers to access sensitive password-reset URLs. The issue occurs via the 'trp_get_translations_regular' AJAX action, exposing plaintext reset keys and login parameters stored in the translation dictionary table. This enables full administrator account takeover if automatic string saving is enabled (default setting) and the target administrator's profile locale is set to a secondary language.

Detection Guidance

Check WordPress sites using TranslatePress for the vulnerable AJAX action 'trp_get_translations_regular' in logs. Look for unauthorized access attempts to translation dictionary tables or administrator password-reset URLs in secondary language dictionaries.

Impact Analysis

Attackers could exploit this to gain full administrative access to your WordPress site, allowing them to take control, modify content, install malware, or steal data. The vulnerability is remotely exploitable without authentication, making it highly dangerous for any site using the affected plugin versions.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR and HIPAA requirements for data protection and access control. A successful exploit may result in non-compliance, potential fines, and reputational damage due to compromised sensitive information.

Mitigation Strategies

Update TranslatePress to the latest version beyond 3.3.1. Disable automatic string saving in settings. Review and remove any exposed password-reset URLs from translation dictionaries. Rotate all administrator account passwords immediately.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19632. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart