CVE-2026-19714: Simple JWT Login < 3.6.8 - Unauthenticated Account Takeover via Missing Google id_token Audience Validation
The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing unauthenticated users to authenticate as any user whose email address such a token carries, up to and including an administrator. Every site with the Simple JWT Login WordPress plugin before 3.6.8's Google sign-in enabled is affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: Simple JWT Loginto a version that resolves this vulnerability.Fixed in 3.6.8 - Compensating control
For sites that cannot be updated immediately, disable Google sign-in for the Simple JWT Login WordPress plugin on all sites where it is currently enabled (affected range: Simple JWT Login before 3.6.8).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19714?
CVE-2026-19714 has a risk rating of 86, indicating a high severity level.
How do I fix CVE-2026-19714?
To fix CVE-2026-19714, update the Simple JWT Login plugin to version 3.6.8 or later.
What vulnerabilities does CVE-2026-19714 introduce?
CVE-2026-19714 allows unauthenticated account takeover by accepting Google identity tokens without audience validation.
Who is affected by CVE-2026-19714?
All WordPress sites using Simple JWT Login versions prior to 3.6.8 are affected by CVE-2026-19714.
What can happen if CVE-2026-19714 is exploited?
If exploited, CVE-2026-19714 can allow attackers to authenticate as any valid user, potentially gaining administrator access.