The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it possible for unauthenticated attackers to extract the raw administrator password-reset URL — including the plaintext reset key and login parameters stored in the translation dictionary table — enabling full administrator account takeover. This vulnerability is only exploitable when automatic string saving is enabled (the default setting) and the target administrator's profile locale is set to a published secondary language, as these conditions cause the password-reset URL to be persisted as a translatable string in the secondary-language dictionary table.
We have discovered 44,625 live websites that are affected by CVE-2026-19632.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 44,625 live websites (100% of TranslatePress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 224 versions ( 100% of all versions) |
| 7,856 websites | |
| 4,806 websites | |
| 2,666 websites | |
| 2,631 websites | |
| 2,165 websites | |
| 2,043 websites | |
| 1,259 websites | |
| 1,118 websites | |
| 1,061 websites | |
| 912 websites |
| .com | 17,785 websites |
| .de | 2,185 websites |
| .org | 1,905 websites |
| .it | 1,745 websites |
| .nl | 1,556 websites |
| .ch | 799 websites |
| .fr | 775 websites |
| .com.br | 768 websites |
| .net | 764 websites |
| .es | 757 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.com | *,*** | ||
| ******.com | *,*** | ||
| ***.com | *,*** | ||
| ********************.com | **,*** | ||
| ******************.de | **,*** | ||
| *******************.com | **,*** | ||
| ***************.org | **,*** | ||
| ***********.co | **,*** | ||
| ******.com | **,*** | ||
| *********.com | **,*** |
FAQ