A critical unauthenticated vulnerability in the TranslatePress – Translate Multilingual sites with AI Translation WordPress plug-in can expose password-reset links and enable takeover of administrator accounts. Tracked as CVE-2026-19632 (CVSS 9.8), the issue affects versions through 3.3.1 and results from a public AJAX endpoint, trp_get_translations_regular, returning translated password-reset email content stored in language dictionaries. Exploitation requires automatic string saving to be enabled and a targeted account—potentially an administrator—to use a published secondary language; attackers can then reset its password and gain full control of the site.
TranslatePress version 3.3.2 fixes the flaw, which affects a plug-in installed on more than 400,000 sites. DigitalOcean honeypot telemetry has recorded exploitation attempts targeting WordPress plug-in weaknesses including this issue, increasing the urgency of patching and configuration reviews. Organizations should verify TranslatePress versions and update immediately; Wordfence released firewall protection to paid customers, while protection for free users is scheduled later. Administrators should also review exposure from the miniOrange SAML 2.0 single-sign-on plug-in, where CVE-2026-15981 and CVE-2026-61979 may allow unauthenticated /wp-admin access as arbitrary users, with patch visibility limited for several paid editions.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
Wordfence released a firewall rule for CVE-2026-19632 to its Premium, Care, and Response customers.
The TranslatePress vendor released version 3.3.2, patching CVE-2026-19632, which affects all versions through 3.3.1 and can enable administrator account takeover.
Wordfence validated CVE-2026-19632 and disclosed the issue to the TranslatePress vendor. The flaw could let unauthenticated attackers obtain administrator password-reset URLs under specific configuration conditions.
A security researcher submitted the critical TranslatePress account-takeover vulnerability, CVE-2026-19632, through the Wordfence Bug Bounty Program.
DigitalOcean observed exploitation attempts targeting the TranslatePress and miniOrange SAML 2.0 vulnerabilities through its honeypot sensor network.
Six paid miniOrange SAML 2.0 editions were patched for CVE-2026-15981 and CVE-2026-61979 without public changelogs or security notifications, leaving the editions absent from vulnerability databases.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceheise.de
Open sourcemalware.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.