KOM CLOUDSERVICE
All Insights

400,000 WordPress Sites, One Plugin, Full Admin Takeover

A flaw in the TranslatePress plugin lets an attacker grab an admin password reset link and own the whole site. Here is what to check today.

If your website runs WordPress and you translate any of it into a second language, stop and check something today. Wordfence disclosed an unauthenticated account takeover flaw in TranslatePress, a translation plugin installed on more than 400,000 sites. Unauthenticated means the attacker does not need a login, a password, or an account of any kind. They just need your site’s address.

What the flaw actually does

Per Wordfence’s advisory, the bug lets an attacker obtain an administrator’s password reset link, use it to reset that account’s password, and log in as the administrator. That is complete site takeover. Not “read some data.” Not “deface a page.” Full control of the account that can install code, add users, and change anything on the site.

There is one condition that narrows it: the reset key only leaks if the target administrator’s profile language is set to a published secondary language. So a single-language English site where every admin is set to English is not in the blast radius. But plenty of small businesses run a Spanish version of their site, or a French one, or they set up multilingual pages a few years ago and forgot the details. And “an admin’s profile language” is not something most owners have ever looked at. If you cannot say for certain what your admins’ language settings are, treat yourself as exposed and patch.

The fix is boring and effective: update TranslatePress to the current version. Do it now rather than at the next maintenance window.

Why this pattern keeps burning small businesses

Five days before the TranslatePress writeup, Wordfence published a nearly identical class of bug in Pods, a plugin on more than 100,000 sites, where unauthenticated attackers could escalate to administrator and overwrite any user’s password, including the site owner’s. Same outcome, different plugin.

This is the WordPress reality. The core platform is maintained well. The plugins are where sites get taken. A typical small business site has fifteen to thirty plugins bolted on over the years by three different people, half of them no longer needed, and nobody has an inventory. Once a disclosure like this goes public, automated scanners start sweeping the internet for vulnerable versions within days. Attackers do not target you specifically. They target the version string. We saw exactly this rhythm with edge devices earlier this month, when ransomware crews jumped on a remote access flaw right after disclosure. Website plugins work the same way, just faster and cheaper for the attacker.

What they do with your website

Owners often shrug at website compromises because “there’s no customer data on there, it’s just a brochure site.” Here is what actually happens.

They inject a payment skimmer or a fake login page and harvest anything your visitors type. They add hidden spam pages that torch your search rankings for months. They plant a redirect that sends a percentage of your visitors to a malware download, which gets your domain flagged by browsers and blocked at other companies’ email gateways. They use your contact form and mail configuration to send phishing from your domain, so your clients get scam invoices that pass every authenticity check because they genuinely came from you. And if your site shares a server or credentials with anything else, they pivot.

For a law firm, an accounting practice, or a medical office, that last one is the killer. A phishing email that arrives from your real domain, referencing a real matter, is close to unstoppable on the recipient’s end.

What to do this week

Update TranslatePress and Pods if you run either. Then log into WordPress and look at Users. Every administrator account should be a person you can name and who still works with you. Delete the web designer from 2021. Delete “admin.” Reset the passwords on the remaining admin accounts and turn on multi-factor authentication for admin logins, which most WordPress security plugins offer for free.

Then do the boring inventory: list every plugin, deactivate and delete anything you are not actively using, and turn on automatic updates for the rest. A plugin you deleted cannot be exploited. A plugin sitting deactivated on the server sometimes still can.

Last, confirm you have a real backup of the site files and the database, stored somewhere the website itself cannot reach. If a takeover happens, the difference between a two-hour restore and a two-week rebuild is entirely that backup.

Website patching is unglamorous and it is exactly the kind of thing that slips for eight months when everybody assumes someone else owns it. It is part of what we watch for clients under managed IT, alongside the endpoint and email side. If you are not sure who is patching your site or when it last happened, that is worth twenty minutes of somebody’s attention. Book a free 15-minute consult and we will tell you straight whether you have a problem.

Talk to the person who'll actually run your IT.

Book a free 15-minute consult. No sales pitch from a stranger, just a straight conversation about what your business needs.

Book your free consult

Or call (732) 701-7012

Monthly agreements, not multi-year lock-ins  ·  No call centers, ever