<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>TranslatePress - Multilingual (&lt;= 3.3.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/translatepress---multilingual--3.3.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 26 Aug 2026 15:23:40 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/translatepress---multilingual--3.3.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Account Takeover in TranslatePress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-08-translatepress-takeover/</link><pubDate>Wed, 26 Aug 2026 15:23:40 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-translatepress-takeover/</guid><description>CVE-2026-19632 allows unauthenticated attackers to hijack user accounts in the TranslatePress - Multilingual WordPress plugin via password reset link disclosure.</description><content:encoded><![CDATA[<p>CVE-2026-19632 is a critical vulnerability affecting the TranslatePress - Multilingual WordPress plugin in versions 3.3.1 and earlier. The vulnerability stems from an insecure implementation that leads to the disclosure of password reset links to unauthenticated users. By successfully triggering this flaw, an attacker can obtain the reset token for any user, including administrative accounts, allowing for complete account takeover.</p>
<p>This vulnerability carries a CVSS score of 9.8, indicating it is easily exploitable over the network without requiring prior authentication or user interaction. Multiple proof-of-concept exploits have been published as of August 26, 2026, significantly increasing the risk of active exploitation against WordPress installations utilizing this plugin. Defenders should prioritize updating to a patched version immediately.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs reconnaissance to identify WordPress sites running vulnerable versions of the TranslatePress plugin.</li>
<li>Attacker probes the target application to identify endpoints related to the password reset functionality.</li>
<li>Attacker crafts an HTTP request targeting the vulnerable plugin logic (CVE-2026-19632) to trigger an unintended password reset action.</li>
<li>The vulnerable plugin discloses the password reset token or link in the application response due to the underlying logic flaw.</li>
<li>Attacker intercepts the reset link or token from the server response.</li>
<li>Attacker uses the captured link to reset the target account password.</li>
<li>Attacker logs into the hijacked account, achieving full unauthorized access.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to gain complete access to any user account within a WordPress site, including accounts with administrative privileges. This can lead to total site compromise, data exfiltration, injection of malicious content, and persistent unauthorized access to the affected environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately update the TranslatePress - Multilingual plugin to the latest version.</li>
<li>Audit WordPress user logs for suspicious password reset requests or unauthorized account access patterns.</li>
<li>Review administrative user accounts for recent changes or unexpected login activity.</li>
<li>Monitor web application logs for high volumes of traffic directed at password reset-related endpoints if remediation is delayed.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">threat</category><category>wordpress</category><category>plugin-vulnerability</category><category>account-takeover</category></item></channel></rss>