Google Authenticator
Google Authenticator has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2016 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 6.5 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Improper Authentication.
Every one of the 2 issues recorded for Google Authenticator has a vendor fix available, so running the current release closes all known holes.
All of these findings were reported by Miguel Mendez Z. Google Authenticator is installed on roughly 20,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
Google Authenticator <= 0.47 - Improper Authentication
Read the full analysisVulnerability Records

Google Authenticator
Author
Ivan
The Google Authenticator plugin for WordPress gives you two-factor authentication using the Google Authenticator app for Android/iPhone/Blackberry. If you are security aware, you may already have the Google Authenticator app installed on your smartphone, using it for two-factor authentication on Gmail/Dropbox/Lastpass/Amazon etc. The two-factor authentication requirement can be enabled on a per-user basis. You could enable it for your administrator account, but log in as usual with less privileged accounts. If You need to maintain your blog using an Android/iPhone app, or any other software using the XMLRPC interface, you can enable the App password feature in this plugin, but please note that enabling the App password feature will make your blog less secure. Credits Thanks to: Miguel Mendez Z for responsibly disclosing a CSRF account lockout vulnerability. Oleksiy for a bugfix in multisite. Paweł Nowacki for the Polish translation Fabio Zumbi for the Portuguese translation Guido Schalkx for the Dutch translation. Henrik.Schack for writing/maintaining versions 0.20 through 0.48 Tobias Bäthge for his code rewrite and German translation. Pascal de Bruijn for his “relaxed mode” idea. Daniel Werl for his usability tips. Dion Hulse for his bugfixes. Aldo Latino for his Italian translation. Kaijia Feng for his Simplified Chinese translation. Alex Concha for his security tips. Jerome Etienne for his jquery-qrcode plugin. Sébastien Prunier for his Spanish and French translation.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C