Executive brief
GPTranslate is a WordPress plugin used to automatically translate website content into multiple languages using AI. A security flaw in this plugin allows an attacker to access and manipulate the website's database without needing a username or password. This could lead to the theft of sensitive customer data, administrative account takeover, or disruption of the website's operations.
Technical details
The GPTranslate plugin for WordPress contains an unauthenticated SQL injection vulnerability due to improper neutralization of special elements used in an SQL command (CWE-89). An attacker can exploit this by sending specially crafted network requests to the affected WordPress site without any prior authentication. Successful exploitation allows the attacker to directly interact with the underlying database, potentially leading to sensitive data exfiltration or unauthorized administrative access. The vulnerability is addressed in version 2.32.7.
Affected products
- GPTranslate GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites <= 2.32.6
Timeline
- 2026-05-27: other: Vulnerability reported by researcher HaiND
- 2026-06-04: advisory: Initial advisory published by Patchstack
- 2026-06-15: disclosed: CVE published in NVD
- 2026-06-04: patched: Version 2.32.7 released to address the issue