CVE

CVE-2026-14204 — Google Authenticator [google-authenticator] < 0.56

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-14204 Google Authenticator [google-authenticator] < 0.56 Cross-Site Request Forgery (CSRF) Unknown < 0.56 0.56 2026-08-03

CVE-2026-14204

The Google Authenticator plugin for WordPress has a security flaw that allows attackers to trick an administrator into performing an unintended action. This is because the plugin does not properly verify the authenticity of certain requests, making it possible for an attacker to send a fake request that the administrator will unwittingly carry out.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.