Executive brief
TranslatePress is a popular WordPress plugin that helps websites support multiple languages. An unauthenticated attacker can exploit an AJAX action in the plugin to extract password-reset URLs containing secret reset keys from the translation database, leading to complete takeover of administrator accounts. The attack succeeds when automatic string saving is enabled (default) and the target admin's language preference is set to a published secondary language.
Technical details
The vulnerability is a sensitive information exposure flaw in the 'trp_get_translations_regular' AJAX action of TranslatePress versions up to 3.3.1. When automatic string saving is enabled, the plugin persists password-reset URLs (including plaintext reset tokens and login parameters) as translatable strings in the translation dictionary table. An unauthenticated attacker can call this AJAX action without authentication to retrieve these sensitive strings from the secondary-language translation table, obtaining the administrator's password-reset link with embedded tokens, resulting in full account takeover. The vulnerability requires the administrator's profile locale to be set to a published secondary language for the reset URL to be stored in an accessible location.
Affected products
- TranslatePress TranslatePress – Translate Multilingual sites with AI Translation up to and including 3.3.1
Timeline
- 2026-08-26: disclosed