TranslatePress - Multilingual is vulnerable to Account Takeover
93
Critical Risk
The unauthenticated trp_get_translations_regular AJAX action returns strings from the secondary-language translation dictionary, including values persisted when automatic string saving is enabled. If an administrator whose profile locale is a published secondary language requests a password reset, that reset URL (with plaintext key and login) can be stored as a translatable string and later read by anyone calling the AJAX endpoint, enabling full account takeover. The fix stops password-reset URLs and similar sensitive strings from being exposed through the translation dictionary API.
You are affected if you are using a version that falls within the vulnerable range with automatic string saving enabled and an administrator whose profile locale is set to a published secondary language.
TranslatePress - Multilingual is vulnerable to Account Takeover in versions 1.0.0 - 3.3.1.
Upgrade the TranslatePress - Multilingual library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.