On August 11, 2026, a significant security vulnerability was reported in TranslatePress, a widely-used WordPress plugin boasting over 400,000 active installations. This vulnerability enables unauthenticated attackers to exploit a password reset link associated with an administrator’s account, effectively allowing them to reset the password and gain full access to the site. Notably, this issue arises only when the target administrator’s profile language is configured to a published secondary language.
The researcher known as momopon1415 discovered and responsibly disclosed this vulnerability through the Wordfence Bug Bounty Program, earning a bounty of $975.00 for their efforts. Wordfence is dedicated to enhancing WordPress security through comprehensive vulnerability research and collaboration with skilled researchers such as momopon1415.
On August 13, 2026, users subscribed to Wordfence Premium, Wordfence Care, and Wordfence Response received a firewall rule designed to protect against known exploits related to this vulnerability in TranslatePress. This update safeguarded their sites hosted on WordPress.org. Meanwhile, users with the free version of Wordfence are set to receive similar protection 30 days later, on September 12, 2026. The firewall rule specifically addresses vulnerabilities within version 3.3.1 of the plugin.
Disclosure and Patch Response
Wordfence fully disclosed the vulnerability details to the Cozmoslabs team via the Wordfence Vulnerability Management Portal on August 12, 2026. The developers acknowledged the report the following day and promptly released a patch for the vulnerability on August 13, 2026. Acknowledgment is due to the Cozmoslabs team for their swift response and effective patch deployment.
All users are strongly encouraged to update to the latest patched version of TranslatePress, which is 3.3.2 at the time of this announcement, as soon as possible to mitigate risk.
Vulnerability Overview
This critical vulnerability can be summarized as follows:
- Affected Plugin: TranslatePress – Multilingual
- Affected Version(s): <= 3.3.1
- Patched Version: 3.3.2
- CVSS Rating: 9.8 (Critical)
- CVE-ID: CVE-2026-19632
- Bounty: $975.00
The vulnerability stems from a combination of behaviors within the plugin that expose the administrator’s password reset link to unauthenticated users. Specifically, when an administrator requests a password reset while their profile is set to a secondary language, the resulting reset email is processed in a way that allows the URL to be stored as a translatable string in a publicly accessible database. An attacker can then leverage this stored URL to reset the administrator’s password.
Security Recommendations
It is crucial to highlight that the exposure of the password reset URL only occurs when the targeted administrator’s profile is set to a published secondary language. If an administrator uses the site’s default language, their reset email is not processed through the translation pipeline, thus preventing leakage.
To better secure your site against this and similar vulnerabilities, enabling Two-Factor Authentication (2FA) on administrator accounts is strongly recommended. While updating to the patched version is essential, 2FA provides an additional safety net. With 2FA activated, even if an attacker alters an administrator’s password, they would still face barriers without the secondary authentication factor.
Furthermore, for enhanced security, consider adopting passwordless logins using passkeys, a newer credentialing method that mitigates the risks associated with password use, making accounts less susceptible to phishing and credential theft.
Disclosure Timeline
- 2026-08-11: Vulnerability submission received.
- 2026-08-12: Report validated and disclosed to developer.
- 2026-08-13: Firewall rule deployed for Premium users, and patched version released.
- 2026-09-12: Firewall rule will be made available for free users.
In conclusion, this blog entry has elucidated a critical Unauthenticated Account Takeover vulnerability in the TranslatePress plugin affecting all versions up to and including 3.3.1. This vulnerability enables attackers to access an administrator’s password reset link from a secondary-language dictionary, potentially compromising the entire site. This issue has been fully resolved in the recently released version 3.3.2.
