Sensitive Information Exposure in TranslatePress Plugin for WordPress
CVE-2026-19632
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 August 2026
What is CVE-2026-19632?
The TranslatePress plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit the 'trp_get_translations_regular' AJAX action. This can lead to the unauthorized extraction of the raw administrator password-reset URL, including sensitive parameters such as the plaintext reset key. The exploitation is facilitated when the default setting for automatic string saving is enabled, and the administrator's profile locale is set to a published secondary language. As a result, the password-reset URL persists as a translatable string in the translation dictionary table, opening the door for potential account takeover.
Affected Version(s)
TranslatePress β Translate Multilingual sites with AI Translation 0 <= 3.3.1