Google Authenticator

Google Authenticator has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2016 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 6.5 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Improper Authentication.

Every one of the 2 issues recorded for Google Authenticator has a vendor fix available, so running the current release closes all known holes.

All of these findings were reported by Miguel Mendez Z. Google Authenticator is installed on roughly 20,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
5.4/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Google Authenticator vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.5

Google Authenticator <= 0.47 - Improper Authentication

Read the full analysis

Vulnerability Records

2 records
Google Authenticator banner
Latestv0.56

Google Authenticator

Ivan

Author

Ivan

4.3(135)
86/100
Last Updated
2026-08-23 (20d ago)
Active Installs
20,000+
Downloads
753,871
Requires WP
4.5+
Requires PHP
0+
Tested up to
WP 7.1
Created
2011-05-16 (16y ago)

The Google Authenticator plugin for WordPress gives you two-factor authentication using the Google Authenticator app for Android/iPhone/Blackberry. If you are security aware, you may already have the Google Authenticator app installed on your smartphone, using it for two-factor authentication on Gmail/Dropbox/Lastpass/Amazon etc. The two-factor authentication requirement can be enabled on a per-user basis. You could enable it for your administrator account, but log in as usual with less privileged accounts. If You need to maintain your blog using an Android/iPhone app, or any other software using the XMLRPC interface, you can enable the App password feature in this plugin, but please note that enabling the App password feature will make your blog less secure. Credits Thanks to: Miguel Mendez Z for responsibly disclosing a CSRF account lockout vulnerability. Oleksiy for a bugfix in multisite. Paweł Nowacki for the Polish translation Fabio Zumbi for the Portuguese translation Guido Schalkx for the Dutch translation. Henrik.Schack for writing/maintaining versions 0.20 through 0.48 Tobias Bäthge for his code rewrite and German translation. Pascal de Bruijn for his “relaxed mode” idea. Daniel Werl for his usability tips. Dion Hulse for his bugfixes. Aldo Latino for his Italian translation. Kaijia Feng for his Simplified Chinese translation. Alex Concha for his security tips. Jerome Etienne for his jquery-qrcode plugin. Sébastien Prunier for his Spanish and French translation.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C