External risk intelligence

Login with Google Plugin Broken Authentication Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-28185

The vulnerability affects a 'Log in with Google' plugin, which is an identity and authentication service designed by nature to be public-facing and reachable over the internet to facilitate user logins for web applications.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the "Log in with Google" plugin affecting how users authenticate. This issue could allow unauthorized access to systems that rely on this plugin for login services. The primary concern is to determine if your organization utilizes this specific plugin and assess potential exposure.

  • Unauthenticated access vulnerability found in login plugin.
  • Critical issue impacts user authentication and system access.
  • Confirm use and assess exposure for your organization.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can leverage a flaw in the "Log in with Google" plugin to bypass authentication controls. This could allow them to gain unauthorized access to user accounts or administrative functions within the affected application, potentially leading to data compromise or system manipulation.

  • No login required.
  • Triggered by the plugin's authentication mechanism.
  • Compromise of account integrity.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in the "Log in with Google" plugin could allow an unauthenticated attacker to bypass authentication when the plugin is used to manage user logins. When supported by the advisory, this could lead to unauthorized access to user accounts.

  • User account access and data.
  • Bypass authentication for unauthorized access.
  • Compromised user accounts.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in the "Log in with Google" plugin impacts authentication and is reachable via the network. Infrastructure and platform teams supporting web applications using this plugin should lead the response, coordinating with security teams. The first practical step is to identify all instances of the affected plugin, confirm their exposure and criticality, and then plan remediation based on business risk.

  • Identify affected plugin instances.
  • Verify reachability and business criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Log in with Google plugin?

The Log in with Google plugin is a software component designed for WordPress sites that allows users to sign into web applications using their existing Google credentials. It simplifies account creation and login processes by offloading authentication to Google's service, acting as an identity bridge between the web application and the user's Google account.

How does CVE-2026-28185 create a security risk?

This vulnerability is classified as Improper Verification of Cryptographic Signature (CWE-345). In plain terms, the plugin fails to properly validate the authentication tokens provided during the login process. Because the check is flawed, the system can be tricked into accepting forged or invalid credentials as legitimate, allowing unauthorized access without proper verification.

Do I need to be logged in for an attacker to trigger this bug?

No, you do not need to be logged in. The vulnerability exists in the plugin's authentication handshake logic, meaning it is accessible to unauthenticated users. An attacker does not need an existing account or prior access to the system to exploit this flaw; they simply need to interact with the login mechanism provided by the plugin.

Why is this plugin considered internet-facing?

According to Halo Surface Signal, this plugin is inherently designed to be public-facing. Because its primary function is to facilitate user logins for web applications, it must remain reachable over the internet to communicate with Google's servers and accept user login attempts. This makes it a standard entry point that is exposed by design.

What should I do first if I use this plugin?

Start by auditing your web environment to locate all instances where this specific plugin is installed. Once identified, evaluate the business criticality of the applications using it. Prioritize securing these systems by coordinating with your technical teams to verify the plugin's current version and preparing to apply updates as soon as they are available to mitigate the risk of unauthorized access.

References