CVE-2026-28185

9.8

rtCamp · Log in with Google

The rtCamp Log in with Google plugin for WordPress versions 1.4.2 and earlier contains an unauthenticated broken authentication vulnerability.

Executive summary

An unauthenticated broken authentication vulnerability in the Log in with Google plugin allows remote attackers to bypass security controls and compromise user accounts.

Vulnerability

This vulnerability (CWE-345) involves insufficient verification of data authenticity during the authentication flow. This allows an unauthenticated attacker to manipulate the login process and potentially gain unauthorized access to the application.

Business impact

A CVSS score of 9.8 indicates a critical risk. Successful exploitation could allow attackers to impersonate legitimate users or administrators, leading to unauthorized data access, privilege escalation, and total compromise of the WordPress site's integrity and confidentiality.

Remediation

Immediate Action: Update the Log in with Google plugin to version 1.4.3 or later immediately to address the authentication flaw.

Proactive Monitoring: Review authentication and login logs for suspicious activity or unauthorized account access patterns.

Compensating Controls: Implement multi-factor authentication at the server or platform level to provide a layer of defense even if the plugin is compromised.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The vulnerability presents a direct risk to the authentication integrity of the affected WordPress site. Administrators must prioritize updating the plugin to the patched version to prevent unauthorized access and potential account takeover.

More rtCamp CVEs