Intel

AIKIDO-2026-268431

TranslatePress - Multilingual is vulnerable to Account Takeover

Account TakeoverCVE-2026-19632 Published 3 days ago

93

Critical Risk

This Affects:

PHPTranslatePress - Multilingual
1.0.0 - 3.3.1
Fixed in 3.3.2
Are you affected? Scan for Free

TL;DR

The unauthenticated trp_get_translations_regular AJAX action returns strings from the secondary-language translation dictionary, including values persisted when automatic string saving is enabled. If an administrator whose profile locale is a published secondary language requests a password reset, that reset URL (with plaintext key and login) can be stored as a translatable string and later read by anyone calling the AJAX endpoint, enabling full account takeover. The fix stops password-reset URLs and similar sensitive strings from being exposed through the translation dictionary API.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range with automatic string saving enabled and an administrator whose profile locale is set to a published secondary language.

Background info

TranslatePress - Multilingual is vulnerable to Account Takeover in versions 1.0.0 - 3.3.1.

How to fix this

Upgrade the TranslatePress - Multilingual library to the patch version.

Links

plugins.trac.wordpress.org/changeset/3645229/translatepress-multilingual
https://plugins.trac.wordpress.org/changeset/3645229/translatepress-multilingual
plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.1/class-translate-press.php#L361
https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.1/class-translate-press.php#L361
plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.1/class-translate-press.php#L531
https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.1/class-translate-press.php#L531
plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.1/includes/class-editor-api-regular-strings.php#L35
https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.1/includes/class-editor-api-regular-strings.php#L35
plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.1/includes/class-editor-api-regular-strings.php#L93
https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.1/includes/class-editor-api-regular-strings.php#L93
plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.1/includes/class-translation-render.php#L2061
https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.1/includes/class-translation-render.php#L2061
plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.1/includes/class-translation-render.php#L2257
https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.1/includes/class-translation-render.php#L2257
plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.1/includes/class-translation-render.php#L2371
https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.1/includes/class-translation-render.php#L2371
plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.1/includes/queries/class-query.php#L1258
https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.1/includes/queries/class-query.php#L1258
wordfence.com/threat-intel/vulnerabilities/id/4f4ebf09-b089-4118-a0ee-399243253f9c?source=cve
https://www.wordfence.com/threat-intel/vulnerabilities/id/4f4ebf09-b089-4118-a0ee-399243253f9c?source=cve

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform