CVE-2026-19714

The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing unauthenticated users to authenticate as any user whose email address such a token carries, up to and including an administrator. Every site with the Simple JWT Login WordPress plugin before 3.6.8's Google sign-in enabled is affected.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-16 06:16

Updated : 2026-08-26 16:30


NVD link : CVE-2026-19714

Mitre link : CVE-2026-19714

CVE.ORG link : CVE-2026-19714


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication