What is CVE-2026-14204?
The Google Authenticator WordPress plugin before version 0.56 lacks CSRF nonce verification when saving two-factor authentication settings, allowing attackers to trick a logged-in user into overwriting their 2FA secret with an attacker-controlled value. This enables the attacker to activate 2FA on the victim's account and subsequently lock them out. Users should urgently update to the latest version.
Azərbaycanca: Google Authenticator WordPress plaqini 0.56-dan əvvəlki versiyalarda iki faktorlu autentifikasiya (2FA) parametrlərini saxlayarkən CSRF nonce yoxlaması aparmır. Bu zəiflik uzaqdan hücum edənə sistemi aldadaraq, daxil olmuş istifadəçinin gizli açarını (2FA secret) öz dəyəri ilə üstələməyə imkan yaradır. Nəticədə hücumçu qurbanın hesabında 2FA-nı aktivləşdirib blok edə bilər, ona görə də plaqini təcili olaraq ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
Which versions of the Google Authenticator plugin are affected by CVE-2026-14204?
The vulnerability affects versions before 0.56, and users are advised to urgently update to the latest version.
What can the lack of CSRF nonce verification in CVE-2026-14204 lead to?
An attacker can trick a logged-in user into overwriting their 2FA secret with an attacker-controlled value, allowing the attacker to activate 2FA on the victim's account and lock them out.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.