On August 11th, 2026, we received a submission for an Unauthenticated Account Takeover vulnerability in TranslatePress, a WordPress plugin with more than 400,000 active installations. This vulnerability makes it possible for unauthenticated attackers to obtain an administrator’s password reset link, reset the account’s password, and log in as that administrator, resulting in complete site takeover. It is important to note that the password reset key is only leaked if the target administrator’s profile language is set to a published secondary language.

Props to momopon1415 who discovered and responsibly reported this vulnerability through the Wordfence Bug Bounty Program. This researcher earned

Click here to continue reading this article.