- Software
- TranslatePress (WordPress plugin)
- Affected versions
- up to and including 3.3.1
- Fixed in
- 3.3.2 (released 13 August 2026)
- Severity
- Critical (CVSS 9.8)
- CVE
- CVE-2026-19632
- Disclosed
- 25 August 2026
→ Update to 3.3.6 or newer, after a backup
A critical vulnerability in TranslatePress, the multilingual plugin used on more than 400,000 WordPress websites, can let an attacker with no account on your site obtain an administrator's password reset link, set a new password and log in as that administrator.
In practice, that means full control of the website.
The flaw is tracked as CVE-2026-19632 and affects TranslatePress up to and including version 3.3.1. The developer, Cozmoslabs, fixed it in version 3.3.2. Later versions also fix other issues, so the safest target today is 3.3.6 or newer.
Is my website affected?
Your website is exposed to this vulnerability if all of the following are true:
- TranslatePress is installed and active
- its version is 3.3.1 or older
- automatic string saving is enabled, which is the plugin's default setting
- at least one administrator has their profile language set to one of the site's published secondary languages
The last condition limits who can be targeted, but it is easy to meet on a multilingual site: an Italian administrator on a site published in English and Italian, for example.
Even if you think the conditions do not apply, update anyway. Settings and user profiles change over time, and older versions contain other known vulnerabilities.
What should I do right now?
1. Check which version you are running
In the WordPress dashboard, go to Plugins → Installed Plugins and look for TranslatePress. The version number is shown under the plugin name.
2. Take a backup
Before updating, make sure you have a recent, complete backup of files and database. On an ecommerce or membership site, check that the backup includes recent orders and registrations.
3. Update TranslatePress
Update to the latest available version, 3.3.6 or newer. Version 3.3.2 is the minimum that fixes CVE-2026-19632.
If you also use TranslatePress add-ons or the Pro version, update them in the same session and check that they are compatible.
4. Test the translated pages
After the update, check the main pages in every language, the language switcher, and any form, checkout or account page that is translated.
5. Look for signs that the vulnerability was used
Updating closes the vulnerability, but it does not undo anything that happened before. Check the points in the next section.
How can I tell if someone used the vulnerability?
Signs worth checking include:
- password reset emails for an administrator that nobody requested
- an administrator who can no longer log in with their usual password
- administrator accounts you do not recognize
- new plugins, themes or files you did not install
- changes to content, settings or redirects that nobody on your team made
- logins to the dashboard from unusual locations or at unusual times
If you find any of these, treat it as a security incident: do not just update and move on. Change the passwords of all administrators, log out every active session and have the website checked for backdoors.
Open a support ticketRunning an older version, such as 2.8.x?
Many websites run TranslatePress versions that are several releases behind. An installation still on 2.8.x is affected by this vulnerability and by other publicly documented issues fixed in later releases, including:
- CVE-2025-58592: deserialization of untrusted data, versions up to 2.10.2, fixed in 2.10.3
- CVE-2026-18510: stored cross-site scripting, versions up to 3.2.6
- CVE-2026-89412: stored cross-site scripting through the Translation Memory suggestion panel, versions up to 3.3.5, fixed in 3.3.6
Jumping across many versions at once is usually fine, but it deserves more care: test the update on a staging copy first if you can, and check custom code, add-ons and translated content afterwards.
What if I cannot update immediately?
Updating is the only complete fix. If you need a few hours or days, these steps can reduce the risk in the meantime:
- use a web application firewall with a rule for this vulnerability (Wordfence and Patchstack have both released protection)
- temporarily set every administrator's profile language to the site's default language
- limit who can reach the WordPress login and password reset pages, where your hosting allows it
These are temporary measures. Plan the update as soon as possible.
How D4Hub can help
D4Hub can take care of the whole process, or only the part you need:
- checking which version of TranslatePress and its add-ons you are running
- backing up the site and updating safely, testing it on a staging copy where possible
- testing translated pages, language switching, forms and checkout after the update
- reviewing administrator accounts, recent changes and logs for signs of misuse
- cleaning the site and closing access if the vulnerability was used
- setting up maintenance so that security updates are applied quickly in the future
For hands-on users: checks with WP-CLI
The following commands are for users who have SSH access and are comfortable with WP-CLI. Run them from the WordPress root folder, and take a backup before changing anything.
Check the installed version
wp plugin get translatepress-multilingual --field=versionUpdate the plugin
wp plugin update translatepress-multilingualList administrator accounts
wp user list --role=administrator --fields=ID,user_login,user_email,user_registeredLook for accounts you do not recognize or that were created recently.
Check an administrator's profile language
wp user meta get <user-id> localeAn empty value means the user follows the site language. A value matching one of your secondary languages (for example it_IT) is one of the conditions for this vulnerability.
Search the access logs
The attack relies on a public request to admin-ajax.php with the action trp_get_translations_regular, combined with a password reset request. If your hosting gives you access to the web server logs, look for those requests around unexpected password reset emails.
D4Hub can help you read the logs and decide whether further investigation is needed.
FAQFrequently asked questions
Version 3.3.2 fixes CVE-2026-19632. Later releases fix other vulnerabilities, including a stored cross-site scripting issue fixed in 3.3.6, so updating to the latest version is the better choice.
When the vulnerability was disclosed, Wordfence reported no confirmed exploitation in the wild. Patchstack classifies it as likely to be targeted by automated mass-exploitation campaigns. Given how easy the attack is, assume that unpatched sites will be targeted.
A firewall rule can block the attack while you update. Wordfence released a rule for its premium users on 13 August 2026 and for free users on 12 September 2026. A firewall rule is not a substitute for updating.
If you see any of the warning signs described above, yes: change every administrator password and end all active sessions. If there are no signs of misuse, updating is the essential step, and reviewing administrator accounts is good practice.
Yes. D4Hub can check the plugins, versions and settings on your website and tell you whether you are affected, before anything is changed.