CVE-2026-19714: Simple JWT Login < 3.6.8 - Unauthenticated Account Takeover via Missing Google id_token Audience Validation

Published Aug 16, 2026
·
Updated

The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing unauthenticated users to authenticate as any user whose email address such a token carries, up to and including an administrator. Every site with the Simple JWT Login WordPress plugin before 3.6.8's Google sign-in enabled is affected.

Affected Software

1 affected component
WordPress plugin "Simple JWT Login"<3.6.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade WordPress plugin: Simple JWT Login to a version that resolves this vulnerability.

    Fixed in 3.6.8
  2. Compensating control

    For sites that cannot be updated immediately, disable Google sign-in for the Simple JWT Login WordPress plugin on all sites where it is currently enabled (affected range: Simple JWT Login before 3.6.8).

Event History

Aug 16, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-19714?

CVE-2026-19714 has a risk rating of 86, indicating a high severity level.

2

How do I fix CVE-2026-19714?

To fix CVE-2026-19714, update the Simple JWT Login plugin to version 3.6.8 or later.

3

What vulnerabilities does CVE-2026-19714 introduce?

CVE-2026-19714 allows unauthenticated account takeover by accepting Google identity tokens without audience validation.

4

Who is affected by CVE-2026-19714?

All WordPress sites using Simple JWT Login versions prior to 3.6.8 are affected by CVE-2026-19714.

5

What can happen if CVE-2026-19714 is exploited?

If exploited, CVE-2026-19714 can allow attackers to authenticate as any valid user, potentially gaining administrator access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203