
PoC for CVE-2026-19632 - TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
Unauthenticated Account Takeover via Password Reset Link Disclosure
If you appreciate my work, consider supporting the project via USDT (TRC20): TQBA72kakjCZLnJt8fJYcD7dyQCEpzNtVN
A complete video walkthrough and demonstration of the script is available here:
CVE-2026-19632 is a critical unauthenticated account takeover vulnerability affecting the TranslatePress – Multilingual WordPress plugin.
## 🚀 Usage
Create a `list.txt` file containing one target per line:
```text
https://target1.example
https://target2.example
https://target3.example
Run:
python3 CVE-2026-19632.py
The tool will prompt:
[?] targets file (list.txt):
Enter:
list.txt
Then:
[?] concurrency (5):
Press Enter to use the default concurrency of 5.
$ python3 CVE-2026-19632.py
[?] targets file (list.txt): list.txt
[+] 3 targets loaded
[?] concurrency (5): 5
[*] https://target1.example
nonce: xxxxxxxxxxxx... langs: en_US,fr_FR default: en_US
users: admin
[1/3] TAKEOVER:0 VULN:1 SAFE:0 ERROR:0
TAKEOVER Takeover stage reached
VULN Vulnerable condition detected
SAFE Target did not match the vulnerable conditions
ERROR An error occurred while processing the target
The tool uses:
list.txt Target list
users.txt Discovered users
shells.txt Shell-related results
⚠️ For authorized security research and testing only.
📚 References CVE Record: https://www.cve.org/CVERecord?id=CVE-2026-19632 Wordfence Advisory: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/translatepress-multilingual/translatepress-multilingual-331-unauthenticated-account-takeover-via-password-reset-link-disclosure TranslatePress: https://wordpress.org/plugins/translatepress-multilingual/ ⚖️ Disclaimer
This project is provided for security research, vulnerability analysis, defensive testing, and authorized penetration testing.
Do not use this research against systems without explicit authorization.
The author is not responsible for misuse or damage caused by this material.
TranslatePress <= 3.3.1