EXECUTIVE SUMMARY:
A critical vulnerability affecting TranslatePress, tracked as CVE-2026-19632 with a CVSS score of 9.8, allows unauthenticated attackers to steal an administrator's password reset link, enabling them to reset the password and seize the account. The flaw is caused by two plugin behaviors that combine badly: automatic string saving being enabled by default and the target admin's locale set to a published secondary language, exposing a public AJAX action that returns dictionary rows to anyone who asks. This vulnerability carries a significant business impact due to its remote exploitation capability and lack of authentication requirements. The attack vector is remote and requires no user interaction, allowing attackers to extract the raw administrator password-reset URL and achieve full administrator account takeover. Exploitation requires two conditions: automatic string saving must be enabled, which is the default setting, and the target administrator's locale must be set to a published secondary language. Patching is essential as no exploitation in the wild has been confirmed; however, the low complexity of exploitation makes immediate remediation necessary.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A critical vulnerability affecting TranslatePress, tracked as CVE-2026-19632 with a CVSS score of 9.8, allows unauthenticated attackers to steal an administrator's password reset link, enabling them to reset the password and seize the account. The flaw is caused by two plugin behaviors that combine badly: automatic string saving being enabled by default and the target admin's locale set to a published secondary language, exposing a public AJAX action that returns dictionary rows to anyone who asks. This vulnerability carries a significant business impact due to its remote exploitation capability and lack of authentication requirements. The attack vector is remote and requires no user interaction, allowing attackers to extract the raw administrator password-reset URL and achieve full administrator account takeover. Exploitation requires two conditions: automatic string saving must be enabled, which is the default setting, and the target administrator's locale must be set to a published secondary language. Patching is essential as no exploitation in the wild has been confirmed; however, the low complexity of exploitation makes immediate remediation necessary.[emaillocker id="1283"]
RECOMMENDATIONS:
REFERENCES:
The following reports contain further technical details:
https://securityonline.info/translatepress-account-takeover-vulnerability/