Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-78267: TranslatePress up to 3.3.2 lets anyone become admin
CVE-2026-78267 · published 10 days ago
Summary
The TranslatePress plugin versions up to 3.3.2 allow a person who is not logged in to gain full administrator privileges on your website. This means an attacker could change settings, install malicious code, or steal data. Update the plugin to the latest version as soon as possible or remove it if you cannot upgrade.
Original advisory text
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-266Incorrect Privilege Assignment
Timeline
Published24 Aug 2026
Updated2 Sep 2026
First seen24 Aug 2026
Sources
CVE-2026-78267 · NVD
Monitor software like this
Free during beta