Skip to content
Critical SQL Injection Vulnerability in GPTranslate Plugin (CVE-2026-49776)

Critical SQL Injection Vulnerability in GPTranslate Plugin (CVE-2026-49776)

First seen 16 Jun 2026, 10:21 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 17, 2026 at 09:44 UTC
  • CVE-2026-49776 is a critical SQL injection vulnerability in GPTranslate plugin for WordPress.
  • The flaw allows unauthenticated attackers to execute arbitrary SQL queries on affected systems.
  • Users must update to version 2.32.7 or later to mitigate the risk of exploitation.

A critical unauthenticated SQL injection vulnerability (CVE-2026-49776) has been identified in the GPTranslate plugin for WordPress, affecting versions 2.32.6 and earlier. This flaw allows attackers to execute arbitrary SQL queries through user-controlled input, potentially exposing sensitive data such as usernames and password hashes. Currently, there is no evidence of public exploitation or proof-of-concept code. A patch has been released, and users are advised to update to version 2.32.7 or later immediately. If updates cannot be applied, disabling or removing the plugin is recommended. The vulnerability has been assigned a CVSS score of 9.3, indicating its critical nature. Security professionals are urged to implement Web Application Firewall (WAF) rules to mitigate potential SQL injection attempts targeting the plugin.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 95d ago How this analysis works

Timeline

2026-06-15
CVE-2026-49776 published
The vulnerability was officially published, detailing the critical SQL injection flaw in GPTranslate plugin versions 2.32.6 and earlier.
Feedly
2026-06-16
Security advisory issued
Security advisories recommend immediate updates or removal of the GPTranslate plugin due to the critical vulnerability.
The Hacker Wire
2026-06-16
Patch released
A patch for the GPTranslate plugin has been released, urging users to update to version 2.32.7 or later.
cve.akaoma.com

More articles in this cluster (5)

Following this threat?

Track CVE-2026-49776 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed