Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-19714: Simple JWT Login WordPress Plugin (Google Sign-in) - Unauthorized User Access

CVE-2026-19714 · published 19 days ago
Summary

The Simple JWT Login WordPress plugin, used for Google sign-in, allows unauthorized users to access any account, including administrator accounts, if they have the correct email address. This affects all sites using the plugin's Google sign-in feature. To fix, update the plugin to version 3.6.8 or later.

What to do
  • Update unknown simple jwt login to version 3.6.8 or later.
Affected software
VendorProductAffected versions
unknown simple jwt login < 3.6.8
Original advisory text
Simple JWT Login < 3.6.8 - Unauthenticated Account Takeover via Missing Google id_token Audience Validation
The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing unauthenticated users to authenticate as any user whose email address such a token carries, up to and including an administrator. Every site with the Simple JWT Login WordPress plugin before 3.6.8's Google sign-in enabled is affected.
Severity
9.1 Critical
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
Timeline
Published16 Aug 2026
Updated1 Sep 2026
First seen16 Aug 2026
Sources
CVE-2026-19714 · MITRE
Monitor software like this
Free during beta