Executive brief
TranslatePress is a popular WordPress plugin that enables website translation into multiple languages. This vulnerability allows unauthenticated attackers to escalate their privileges to administrator level, granting them complete control over a WordPress site including access to all content, user accounts, and configuration settings.
Technical details
This is an unauthenticated privilege escalation vulnerability (CWE-269: Improper Access Control) in TranslatePress affecting versions up to 3.3.2. The vulnerability allows an unauthenticated or low-privilege user to gain administrative access to the WordPress installation. The attack vector is network-based with no authentication required. An attacker exploiting this flaw can assume full administrative privileges and perform any action on the affected WordPress site. The vulnerability has been patched in version 3.3.3 and later.
Affected products
- Cozmoslabs TranslatePress <= 3.3.2
Timeline
- 2026-08-24: disclosed: CVE-2026-78267 published on NVD
- 2026-08-24: patched: Version 3.3.3 released as patch
- 2026-08-09: reported: Reported to Patchstack by ChuongVN