Account Takeover Flaw Hits TranslatePress Plugin Used on 400K WordPress Sites
The vulnerability, CVE-2026-19632, exposes WordPress admin password-reset links through TranslatePress, allowing unauthenticated attackers to take over affected WordPress websites.