cvedb.io
CVE-2026-14204
UNKNOWN · CVSS n/a
EPSS exploitation probability: 0%
Published 2026-08-06T07:16:27.430 · Last modified 2026-08-06T07:16:27.430

Summary

The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing attackers to trick a logged-in user into overwriting their own 2FA secret with an attacker-controlled value, which enables two-factor authentication and locks the victim out of their account.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.