Feed/CVE-2026-14204
CVE-2026-14204MEDIUMCVSS 6.5

CVE-2026-14204

Published Aug 6, 2026·Updated Aug 6, 2026

NVD Description

The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing attackers to trick a logged-in user into overwriting their own 2FA secret with an attacker-controlled value, which enables two-factor authentication and locks the victim out of their account.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free