The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without the one-time code and bypass enforced two-factor authentication for any account, including administrators. The affected two-factor module ships only in the premium build.
Metrics
Affected Vendors & Products
References
History
Thu, 23 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-287 | |
| Metrics |
cvssV3_1
|
Thu, 23 Jul 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without the one-time code and bypass enforced two-factor authentication for any account, including administrators. The affected two-factor module ships only in the premium build. | |
| Title | Security Ninja (Premium) < 5.290 - Two-Factor Authentication Bypass via secnin_skip_2fa | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-07-23T14:10:42.101Z
Reserved: 2026-07-01T08:48:39.322Z
Link: CVE-2026-14291
Updated: 2026-07-23T14:10:36.716Z
No data.
No data.
OpenCVE Enrichment
No data.