AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-14204

MEDIUM · CVSS 6.5 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Google Authenticator WordPress plugin prior to version 0.56 is vulnerable due to a lack of CSRF nonce verification when saving two-factor authentication settings. This flaw allows attackers to manipulate a logged-in user's 2FA setup, potentially locking them out of their account by replacing their authentication secret with a malicious one. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of account takeover.

CVE
CVE-2026-14204
Severity
MEDIUM
CVSS
6.5
EPSS
0.12%
WordPress

Original NVD Description

The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing attackers to trick a logged-in user into overwriting their own 2FA secret with an attacker-controlled value, which enables two-factor authentication and locks the victim out of their account.