WordPress translation plugin exposes admin reset tokens to visitors
A vulnerability in a WordPress translation plugin reportedly leaks administrator password-reset tokens to any visitor, putting about 400,000 sites at risk.
By DoomRadar · Published on DoomRadar .
Why it matters
Attackers could use exposed tokens to gain administrative control over a large number of websites.
Related source links
These links were collected with this event. Recorded source dates may reflect when a link was found. Article publication dates are shown only when available from the source. Open the originals for their full context.
- WordPress Translation Plugin Leaks Admin Reset Tokens to Any Visitor: 400,000 Sites at Risk ↗techtimes.com · Recorded source date: Aug 27, 2026, 9:16 PM UTC
AI-assisted, source-based analysis. Methodology · Report a correction