CVE case study
CVE-2026-28185: Broken Authentication in the Log in with Google Plugin
A broken-authentication flaw in the Log in with Google plugin through 1.4.2 could let an unauthenticated request reach an authenticated outcome and gain admin access. Version 1.4.3 closes the gap.
- Weakness
- Broken Authentication
- Affected
- Log in with Google 1.4.2 and earlier
- Remediation state
- Upgrade to Log in with Google 1.4.3 or later
- Advisory published
- 13 Aug 2026
Why it matters
The Log in with Google plugin handles the Google sign-in flow for WordPress. Through version 1.4.2, a broken-authentication flaw let an unauthenticated request reach an authenticated outcome it should not.
The public record scores the issue Critical at 9.8 and notes it can grant administrator access. Version 1.4.3 closes the gap.