WordPress Plugin Vulnerabilities

Google Authenticator < 0.56 - 2FA Secret Overwrite via CSRF

Description

The plugin does not verify a CSRF nonce when saving its two-factor setup, allowing attackers to trick a logged-in user into overwriting their own 2FA secret with an attacker-controlled value, which enables two-factor authentication and locks the victim out of their account.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
Miguel Mendez Z
Submitter
Miguel Mendez Z
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-08-03 (about 25 days ago)
Added
2026-08-03 (about 24 days ago)
Last Updated
2026-08-03 (about 24 days ago)

Other