400,000 WordPress Sites Affected by Account Takeover Vulnerability in TranslatePress WordPress Plugin

On August 11th, 2026, we received a submission for an Unauthenticated Account Takeover vulnerability in TranslatePress, a WordPress plugin with more than 400,000 active installations. This vulnerability makes it possible for unauthenticated attackers to obtain an administrator's password reset link, reset the account's password, and log in as that administrator, resulting in complete site takeover.

This article has been indexed from Blog – Wordfence

Read the original article: