Skip to main content
QUIETLYTIC
Vulnerability

TranslatePress – Translate Multilingual sites with AI Translation Vulnerability (CVE-2026-19632)

CVE-2026-19632 is a CVSS 9.8 flaw in the TranslatePress WordPress plugin exposing admin password-reset URLs, reported exploited by VulnCheck.

CVE-2026-19632
Threat Level
CRITICAL
CVSS
9.8
Status
Active Exploitation
Confidence
Medium
Affected Products
TranslatePress – Translate Multilingual sites with AI Translation, TranslatePress (through 3.3.1)

CVE-2026-19632 carries a CVSS 3.1 base score of 9.8 against TranslatePress – Translate Multilingual sites with AI Translation, a WordPress plugin published by Cozmoslabs for building multilingual sites. NVD classifies it as CWE-640 (Weak Password Recovery Mechanism for Forgotten Password) and states the affected range as versions up to and including 3.3.1. VulnCheck’s KEV feed reports the CVE as exploited, dated August 25, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2026-19632 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog admits vendor and researcher exploitation reporting on broader criteria than CISA’s own listing process has accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s description is unusually specific about both the mechanism and its two preconditions. TranslatePress’s trp_get_translations_regular AJAX action can be used to extract translatable strings from the plugin’s own dictionary table. NVD states that under two conditions — automatic string saving enabled (the plugin’s default setting) and a target administrator’s profile locale set to a published secondary language — WordPress’s password-reset URL, including the plaintext reset key, ends up persisted as a translatable string in that dictionary table. Because the AJAX action that reads translatable strings requires no authentication, an attacker can extract that stored URL directly, obtaining a valid password-reset link for the targeted Administrator account without ever triggering WordPress’s own reset-email flow.

Both preconditions matter for assessing exposure: automatic string saving is the plugin’s default behavior, so most installations satisfy that condition without any explicit configuration choice, but the second condition — an administrator’s own account being configured with a secondary-language locale — depends on how a specific site’s administrators have set up their individual profiles.

Evidence and confidence

  • Medium confidence — the CVSS 9.8 score, the vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), the CWE-640 classification, the affected-version ceiling (3.3.1), and the full two-condition mechanism all trace to NVD alone. The exploitation report traces to VulnCheck KEV alone.
  • High exploitation probability — FIRST’s EPSS model scores this CVE at 0.02493, an 83.8th percentile score as of our ingestion.

No field is in conflict between our two sources. Our data carries no fixed-version field; NVD’s description states only the affected ceiling.

Why this matters

This vulnerability doesn’t fail in the way a typical “leaked credential” story does — no password is exposed, and WordPress’s own reset-email delivery is never triggered, which means the site’s own account-recovery audit trail (an email sent, a link clicked) shows nothing unusual. An attacker with a live reset URL can take over the account entirely outside the channels a site operator would normally think to monitor for this kind of attack.

Because one of the two preconditions (an administrator’s own profile locale) is not something a version check can reveal, site operators running TranslatePress up to 3.3.1 should not assume they’re safe simply because a Google search doesn’t surface obvious signs of compromise; the safer approach is to check whether automatic string saving is enabled and whether any administrator account uses a secondary-language locale, and to upgrade regardless of that check’s outcome.

Frequently Asked Questions

What is CVE-2026-19632? A CVSS 9.8 vulnerability (CWE-640) in the TranslatePress WordPress plugin, through version 3.3.1, that NVD states allows unauthenticated attackers to extract an administrator’s password-reset URL from the plugin’s translation dictionary table under specific conditions.

Is CVE-2026-19632 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated August 25, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 19, 2026 ingestion, and we have no independent corroboration.

What conditions does this require? NVD states two conditions: automatic string saving must be enabled (the plugin’s default setting) and the targeted administrator’s profile locale must be set to a published secondary language.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Which version fixes this? Our data carries no fixed-version field. NVD states versions through 3.3.1 are affected; confirm directly with the vendor’s changelog whether a later release addresses this specific CVE.


Severity, vector, weakness classification, and the full two-condition mechanism sourced from the National Vulnerability Database record for CVE-2026-19632. Exploitation status and the August 25, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools