A critical vulnerability in TranslatePress, a multilingual plugin installed on more than 400,000 WordPress sites, lets an attacker take over your administrator account without ever logging in.

What happened

Wordfence says the flaw lets an unauthenticated attacker obtain the password reset link WordPress generates for an administrator account. With that link, the attacker resets the admin’s password and logs in, gaining full control of the site.

The bug only fires under one specific condition: the target administrator’s profile language must be set to a published secondary language on the site, not the site’s default language. If your site runs TranslatePress to serve content in multiple languages and any admin has their profile set to one of those secondary languages, you’re exposed.

A researcher using the handle momopon1415 found and reported the flaw through the Wordfence Bug Bounty Program, earning a $975 payout. Wordfence says it issued a firewall rule to Premium, Care, and Response customers on August 13, 2026, to block known exploit attempts. Wordfence’s free version, used on most sites, doesn’t get that same protection until 30 days after disclosure, on September 12, 2026.

What to do

  1. Update TranslatePress to the latest version from your WordPress dashboard right away.
  2. Check whether any administrator on your site has their profile language set to a secondary language rather than the site default. If so, treat that account as at risk until you’ve confirmed the plugin is updated.
  3. If you use the free version of Wordfence, don’t wait for the firewall rule to reach you in September. Updating the plugin now removes the risk regardless of which Wordfence tier you run.
  4. Review your admin user list for accounts you don’t recognize and check recent login activity for anything unusual since August 11, 2026, when the vulnerability was first reported.

Site owners running any multilingual setup with TranslatePress should treat this as an immediate update, not a routine one.


End of article