Junglewise Threat Intelligence

CVE-2026-78267: TranslatePress privilege escalation in multilingual plugin

CVE-2026-78267 · Severity: critical · CVSS 9.8 · Published 2026-08-24

Vendors: Cozmoslabs.

Executive brief

TranslatePress is a popular WordPress plugin that enables website translation into multiple languages. This vulnerability allows unauthenticated attackers to escalate their privileges to administrator level, granting them complete control over a WordPress site including access to all content, user accounts, and configuration settings.

Technical details

This is an unauthenticated privilege escalation vulnerability (CWE-269: Improper Access Control) in TranslatePress affecting versions up to 3.3.2. The vulnerability allows an unauthenticated or low-privilege user to gain administrative access to the WordPress installation. The attack vector is network-based with no authentication required. An attacker exploiting this flaw can assume full administrative privileges and perform any action on the affected WordPress site. The vulnerability has been patched in version 3.3.3 and later.

Affected products

  • Cozmoslabs TranslatePress <= 3.3.2

Timeline

  • 2026-08-24: disclosed: CVE-2026-78267 published on NVD
  • 2026-08-24: patched: Version 3.3.3 released as patch
  • 2026-08-09: reported: Reported to Patchstack by ChuongVN

References