WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Google Authenticator

Google Authenticator for your WordPress blog.

6Reported vulnerabilities
8.1Highest CVSS score
0.56Latest version
20,000+Active installs

What to do now

Update Google Authenticator to 0.56 or later. 6 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 28, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2022-0229 High 8.1 0.6% Before 5.5 5.5 March 21, 2022
CVE-2022-1321 Medium 4.8 0.6% Before 5.5.6 5.5.6 June 27, 2022
CVE-2022-0875 Medium 4.3 0.4% Before 1.0.5 1.0.5 June 27, 2022
WF-f3bbc23b-94af-4f4f-8b5f-6af41108fd93 Medium 6.5 0.47 and earlier 0.48 April 28, 2016
CVE-2022-4943 Medium 5.3 0.5% 5.6.5 and earlier 5.6.6 October 20, 2023
CVE-2026-14204 Medium 4.3 0.1% 0.55 and earlier 0.56 August 3, 2026

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.