400,000 WordPress Sites Impacted by Account Takeover Vuln in TranslatePress Plugin
Researchers have uncovered a critical vulnerability with a CVSS score of 9.8 in the TranslatePress WordPress plugin, with 400,000 active installations, that could allow unauthenticated attackers to extract the raw administrator password-reset URL — including the plaintext reset key and login…