THREAT OPS › Threat News › 400,000 WordPress Sites Affected by Account Takeover Vulnerability in TranslatePress WordPress Plugin
400,000 WordPress Sites Affected by Account Takeover Vulnerability in TranslatePress WordPress Plugin
<p>On August 11th, 2026, we received a submission for an Unauthenticated Account Takeover vulnerability in <a href="https://wordpress.org/plugins/translatepress-multilingual/" rel="noopener" target="_blank">TranslatePress</a>, a WordPress plugin with more than 400,000 active installations. This vulnerability makes it possible for unauthenticated attackers to obtain an administrator’s passwor
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- 0f962dd7143eb1e6e46c9632a10cf4cfmd5
- CVE-2026-19632cve
- https://wordpress.org/plugins/translatepress-multilingual/url
- https://www.cve.org/CVERecord?id=CVE-2026-19632url
- www.gravatar.comdomain