{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/translatepress---multilingual--3.3.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["TranslatePress - Multilingual (\u003c= 3.3.1)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","plugin-vulnerability","account-takeover"],"_cs_type":"threat","_cs_vendors":[],"content_html":"\u003cp\u003eCVE-2026-19632 is a critical vulnerability affecting the TranslatePress - Multilingual WordPress plugin in versions 3.3.1 and earlier. The vulnerability stems from an insecure implementation that leads to the disclosure of password reset links to unauthenticated users. By successfully triggering this flaw, an attacker can obtain the reset token for any user, including administrative accounts, allowing for complete account takeover.\u003c/p\u003e\n\u003cp\u003eThis vulnerability carries a CVSS score of 9.8, indicating it is easily exploitable over the network without requiring prior authentication or user interaction. Multiple proof-of-concept exploits have been published as of August 26, 2026, significantly increasing the risk of active exploitation against WordPress installations utilizing this plugin. Defenders should prioritize updating to a patched version immediately.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify WordPress sites running vulnerable versions of the TranslatePress plugin.\u003c/li\u003e\n\u003cli\u003eAttacker probes the target application to identify endpoints related to the password reset functionality.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP request targeting the vulnerable plugin logic (CVE-2026-19632) to trigger an unintended password reset action.\u003c/li\u003e\n\u003cli\u003eThe vulnerable plugin discloses the password reset token or link in the application response due to the underlying logic flaw.\u003c/li\u003e\n\u003cli\u003eAttacker intercepts the reset link or token from the server response.\u003c/li\u003e\n\u003cli\u003eAttacker uses the captured link to reset the target account password.\u003c/li\u003e\n\u003cli\u003eAttacker logs into the hijacked account, achieving full unauthorized access.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to gain complete access to any user account within a WordPress site, including accounts with administrative privileges. This can lead to total site compromise, data exfiltration, injection of malicious content, and persistent unauthorized access to the affected environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the TranslatePress - Multilingual plugin to the latest version.\u003c/li\u003e\n\u003cli\u003eAudit WordPress user logs for suspicious password reset requests or unauthorized account access patterns.\u003c/li\u003e\n\u003cli\u003eReview administrative user accounts for recent changes or unexpected login activity.\u003c/li\u003e\n\u003cli\u003eMonitor web application logs for high volumes of traffic directed at password reset-related endpoints if remediation is delayed.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-26T15:23:40Z","date_published":"2026-08-26T15:23:40Z","id":"https://feed.craftedsignal.io/briefs/2026-08-translatepress-takeover/","summary":"CVE-2026-19632 allows unauthenticated attackers to hijack user accounts in the TranslatePress - Multilingual WordPress plugin via password reset link disclosure.","title":"Unauthenticated Account Takeover in TranslatePress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-translatepress-takeover/"}],"language":"en","title":"CraftedSignal Threat Feed - TranslatePress - Multilingual (\u003c= 3.3.1)","version":"https://jsonfeed.org/version/1.1"}