img
HostingBag
Author Name

HostingBag

Categories

WordPress Security

Date

06/09/2026

WordPress TranslatePress Hack: 400,000 Sites at Risk of Account Takeover

WordPress site owners and hosting teams should review TranslatePress installations after Wordfence disclosed an unauthenticated account-takeover vulnerability affecting more than 400,000 active installations.

What happened?

The vulnerability could allow an unauthenticated attacker to obtain an administrator password-reset link and take over the account. The issue depends on the target administrator profile using a published secondary language, but exposed sites can still face complete administrative compromise.

Wordfence reported the issue to the TranslatePress developer on 12 August 2026. The vendor released the patched version 3.3.2 on 13 August 2026. Wordfence recommends updating as soon as possible.

What hosting teams should check

  • Inventory every WordPress installation using TranslatePress or the TranslatePress Multilingual plugin.
  • Update the plugin to version 3.3.2 or the latest available patched release.
  • Review administrator accounts, password-reset activity, login history, and newly created users.
  • Check for unexpected plugin, theme, media, or scheduled-task changes.
  • Require multi-factor authentication for administrator accounts and use unique passwords.
  • Keep isolated backups and test restoration before an incident occurs.

Why this matters for managed hosting

A vulnerable WordPress plugin can turn a single compromised administrator account into a wider hosting incident. After patching, hosting teams should monitor authentication events, scan affected sites, and confirm that backups and file-integrity checks are working.

Recommended action

Update TranslatePress immediately, then review administrator access and recent site changes. If compromise is suspected, isolate the site, preserve logs, rotate credentials, remove unauthorized access, and restore only from a trusted backup.

Sources: Wordfence vulnerability disclosure and WordPress 7.0.4 security release.

Share this Post :