SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-19714

CRITICAL · CVSS 9.1 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-08-16 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Simple JWT Login plugin for WordPress versions prior to 3.6.8 is vulnerable due to inadequate validation of Google identity tokens, enabling unauthenticated users to impersonate any user, including administrators, based on the email address contained in the token. This flaw poses a significant security risk for any WordPress site utilizing this plugin with Google sign-in enabled. WordPress administrators using this plugin should prioritize immediate updates to mitigate potential unauthorized access.

CVE
CVE-2026-19714
Severity
CRITICAL
CVSS
9.1
EPSS
0.32%
WordPress

Original NVD Description

The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing unauthenticated users to authenticate as any user whose email address such a token carries, up to and including an administrator. Every site with the Simple JWT Login WordPress plugin before 3.6.8's Google sign-in enabled is affected.