ThreatCluster

Critical WordPress Plugin Vulnerabilities Allow Admin Account Takeover

First seen 26 Aug 2026, 14:23 UTC Gbhackers 72

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities have been identified in popular WordPress plugins, TranslatePress and Pods, allowing unauthenticated attackers to take control of administrator accounts. The TranslatePress vulnerability, tracked as CVE-2026-19632, has a CVSS score of 9.8 and affects all versions up to 3.3.1, impacting over 400,000 sites. The Pods vulnerability, tracked as CVE-2026-19598, also carries a CVSS score of 9.8 and affects versions up to a certain unspecified version. The CVE-2026-19598 was first made public on August 15, 2026, with a proof-of-concept released on August 19, 2026. Both vulnerabilities pose significant risks to website security, and administrators are urged to take immediate action to mitigate these threats. The current status of the TranslatePress vulnerability is that it was published on August 26, 2026, indicating an urgent need for patching.

Key Points: • CVE-2026-19632 in TranslatePress allows admin takeover on 400,000+ sites. • CVE-2026-19598 in Pods also enables unauthenticated admin access. • Both vulnerabilities have a CVSS score of 9.8, indicating critical severity.

Timeline

2026-08-15
CVE-2026-19598 published
A critical vulnerability in the Pods plugin was disclosed, affecting multiple versions.
Gbhackers
2026-08-19
First public PoC for CVE-2026-19598
Proof-of-concept code for the Pods vulnerability was released, increasing exploitation risk.
Gbhackers
2026-08-26
CVE-2026-19632 published
A critical vulnerability in the TranslatePress plugin was disclosed, affecting all versions up to 3.3.1.
Gbhackers