Skip to content
CVE-2026-49776 - Exploits & Severity

CVE-2026-49776 - Exploits & Severity

Feedly June 16, 2026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)

Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress plugin version 2.32.6 and earlier. The vulnerability allows attackers to execute arbitrary SQL queries through user-controlled input without authentication.

An unauthenticated attacker over the network can execute arbitrary SQL queries to read sensitive data from the WordPress database, including usernames, password hashes, email addresses, and other stored information.

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

Patch available - update GPTranslate plugin to version 2.32.7 or later

Immediately update the GPTranslate plugin to the latest patched version (2.32.7+). If an update is not immediately available, disable or remove the plugin until patching is complete. Implement Web Application Firewall (WAF) rules to detect and block SQL injection attempts targeting the affected plugin endpoints.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L

Feedly found the first article mentioning CVE-2026-49776 . See article

NVD published the first details for CVE-2026-49776

A CVSS base score of 9.3 has been assigned.

[GHSA-2f68-qpff-692q] Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for W

CVE-2026-49776 | JExtensions Store GPTranslate Plugin up to 2.32.6 on WordPress sql injection

🔴 CVE-2026-49776 - Critical (9.3) Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Autom... #infosec #cybersecurity #CVE #vulnerability #security #patchstack

CVE-2026-49776 - WordPress GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin CVE ID : CVE-2026-49776 Published : June 15, 2026, 8:19 p.m. | 49 minutes ago Description : Unauthenticated SQL Injection in GPTranslate – Multilin...

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities

Attack Types (1)

CWE Weaknesses (1)

Platforms (1)