Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
TranslatePress

TranslatePress Vendor Cyber Rating & Cyber Score

translatepress.com

The WordPress translation plugin that anyone can use.


TranslatePress A.I CyberSecurity Scoring

TranslatePress
Company Information
Website:https://translatepress.com/
Employees number:5
Number of followers:93
NAICS:541511
Industry Type:IT System Custom Software Development
Homepage:translatepress.com
TranslatePress Risk Score (AI oriented)
Between 700 and 749
logo
TranslatePressIT System Custom Software Development
Updated:
26/08/2026
749/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
TranslatePress Global Score (TPRM)
xxxx
logo
TranslatePressIT System Custom Software Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

TranslatePressModerate
Current Score
749Ba (MODERATE)
01000
1 incidents
-1 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
749Before Incident
AUGUST 2026
750Before Incident
Vulnerability
13 Aug 2026TranslatePress
Cozmoslabs: WordPress Plugin Vulnerability Exposes 400,000 Sites to Account Takeover Attacks

Critical TranslatePress WordPress Plugin Vulnerability Exposes Sites to Admin Account Takeover

749After Incident
CRITICAL-1
TRA1787739836
Critical TranslatePress WordPress Plugin Vulnerability Exposes Sites to Admin Account Takeover A severe security flaw in the TranslatePress WordPress plugin (CVE-2026-19632) could allow unauthenticated attackers to hijack administrator accounts and fully compromise affected websites. The vulnerability, rated 9.8 (critical) on the CVSS scale, impacts all versions of TranslatePress up to 3.3.1, with a patch released in version 3.3.2. The issue was discovered by security researcher momopon1415, who reported it through the Wordfence Bug Bounty Program and received a $975 reward. The flaw stems from how TranslatePress processes password reset emails and stores translatable strings. When an administrator requests a password reset, WordPress generates a reset URL containing a plaintext key. Under specific conditions including automatic string saving (enabled by default) and an administrator profile set to a published secondary language the plugin stores this sensitive URL in a translation dictionary table. Attackers could exploit this by using the plugin’s publicly accessible `trp_get_translations_regular` AJAX action to retrieve stored translation entries, including the password reset link. With knowledge of an administrator’s username or email, an attacker could trigger a reset, extract the exposed URL, set a new password, and gain full administrative access. Successful exploitation grants attackers control over the WordPress site, enabling them to create privileged accounts, install malicious plugins/themes, alter content, steal data, or distribute malware. The risk is particularly high for businesses, e-commerce stores, and publishers using TranslatePress. The vulnerability was reported to Wordfence on August 11, 2026, disclosed to the plugin developer Cozmoslabs on August 12, and patched in version 3.3.2 on August 13. Notably, the flaw only affects sites where administrators use a published secondary language those with default language settings are not impacted.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Data Compromised: Administrator account credentials, site content, customer data (if applicable)Systems Affected: WordPress sites using TranslatePress plugin (versions up to 3.3.1)Operational Impact: Full administrative access to WordPress sites, potential malware distribution, data theft, or content alterationBrand Reputation Impact: High (potential for malware distribution, data breaches, or defacement)Identity Theft Risk: High (if personally identifiable information is accessed)Payment Information Risk: High (if e-commerce sites are affected)
DATA BREACH
Type Of Data Compromised: Administrator credentials, site content, customer data (if applicable)Sensitivity Of Data: High (administrative access, PII, payment information if e-commerce)Personally Identifiable Information: Potential (if accessed by attackers)
JULY 2026
750Before Incident
JUNE 2026
750Before Incident
MAY 2026
750Before Incident
APRIL 2026
750Before Incident
MARCH 2026
750Before Incident
FEBRUARY 2026
750Before Incident
JANUARY 2026
750Before Incident
DECEMBER 2025
750Before Incident
NOVEMBER 2025
750Before Incident
OCTOBER 2025
750Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for TranslatePress ?
?
What was TranslatePress's A.I Rankiteo Cyber Score in August 2026 ?
?
What was TranslatePress's A.I Rankiteo Cyber Score in July 2026 ?
?
What was TranslatePress's A.I Rankiteo Cyber Score in June 2026 ?
?
What was TranslatePress's A.I Rankiteo Cyber Score in May 2026 ?
?
What was TranslatePress's A.I Rankiteo Cyber Score in April 2026 ?
?
What was TranslatePress's A.I Rankiteo Cyber Score in March 2026 ?
?
What was TranslatePress's A.I Rankiteo Cyber Score in February 2026 ?
?
What was TranslatePress's A.I Rankiteo Cyber Score in January 2026 ?
?
What was TranslatePress's A.I Rankiteo Cyber Score in December 2025 ?
?
What was TranslatePress's A.I Rankiteo Cyber Score in November 2025 ?
?
What was TranslatePress's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on TranslatePress's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with TranslatePress ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view TranslatePress's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?