← DOOMRADAR

cyber · Published brief

WordPress translation plugin exposes admin reset tokens to visitors

A vulnerability in a WordPress translation plugin reportedly leaks administrator password-reset tokens to any visitor, putting about 400,000 sites at risk.

By DoomRadar · Published on DoomRadar .

Why it matters

Attackers could use exposed tokens to gain administrative control over a large number of websites.

Related source links

These links were collected with this event. Recorded source dates may reflect when a link was found. Article publication dates are shown only when available from the source. Open the originals for their full context.

  1. WordPress Translation Plugin Leaks Admin Reset Tokens to Any Visitor: 400,000 Sites at Risk ↗techtimes.com · Recorded source date: Aug 27, 2026, 9:16 PM UTC

AI-assisted, source-based analysis. Methodology · Report a correction