CVE case study

CVE-2026-28185: Broken Authentication in the Log in with Google Plugin

A broken-authentication flaw in the Log in with Google plugin through 1.4.2 could let an unauthenticated request reach an authenticated outcome and gain admin access. Version 1.4.3 closes the gap.

Weakness
Broken Authentication
Affected
Log in with Google 1.4.2 and earlier
Remediation state
Upgrade to Log in with Google 1.4.3 or later
Advisory published
13 Aug 2026

Why it matters

The Log in with Google plugin handles the Google sign-in flow for WordPress. Through version 1.4.2, a broken-authentication flaw let an unauthenticated request reach an authenticated outcome it should not.

The public record scores the issue Critical at 9.8 and notes it can grant administrator access. Version 1.4.3 closes the gap.

References

Further reading

Evidence connected to this article.

Back to article start