CVE-2026-19714: CWE-287 Improper Authentication in Simple JWT Login
Simple JWT Login WordPress plugin versions before 3.6.8 with Google sign-in enabled do not validate the audience field of Google identity tokens. This flaw allows unauthenticated users to impersonate any user, including administrators, by presenting a token with the victim's email address. The vulnerability arises from improper authentication checks in the plugin's handling of Google tokens.
AI Analysis
Technical Summary
The Simple JWT Login WordPress plugin prior to version 3.6.8 fails to validate the audience claim in Google identity tokens it accepts for authentication. This improper authentication (CWE-287) allows attackers to authenticate as any user whose email is contained in a token, potentially gaining administrative access. The issue affects all sites using the plugin with Google sign-in enabled before the fixed version. No CVSS score or official patch information is provided in the source data.
Potential Impact
An attacker can bypass authentication controls by exploiting the lack of audience validation in Google identity tokens, allowing them to impersonate any user, including administrators. This can lead to full site compromise depending on the privileges of the impersonated user.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, disabling Google sign-in in the Simple JWT Login plugin or upgrading to version 3.6.8 or later (once confirmed) is recommended to prevent exploitation.
CVE-2026-19714: CWE-287 Improper Authentication in Simple JWT Login
Description
Simple JWT Login WordPress plugin versions before 3.6.8 with Google sign-in enabled do not validate the audience field of Google identity tokens. This flaw allows unauthenticated users to impersonate any user, including administrators, by presenting a token with the victim's email address. The vulnerability arises from improper authentication checks in the plugin's handling of Google tokens.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Simple JWT Login WordPress plugin prior to version 3.6.8 fails to validate the audience claim in Google identity tokens it accepts for authentication. This improper authentication (CWE-287) allows attackers to authenticate as any user whose email is contained in a token, potentially gaining administrative access. The issue affects all sites using the plugin with Google sign-in enabled before the fixed version. No CVSS score or official patch information is provided in the source data.
Potential Impact
An attacker can bypass authentication controls by exploiting the lack of audience validation in Google identity tokens, allowing them to impersonate any user, including administrators. This can lead to full site compromise depending on the privileges of the impersonated user.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, disabling Google sign-in in the Simple JWT Login plugin or upgrading to version 3.6.8 or later (once confirmed) is recommended to prevent exploitation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-08-13T11:24:49.631Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a8154acbf8831d53998d6f0
Added to database: 08/16/2026, 06:11:56 UTC
Last enriched: 08/16/2026, 06:29:05 UTC
Last updated: 08/16/2026, 06:47:33 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.