CVE-2026-14291
Received Received - Intake

Security-Ninja-Premium WordPress Plugin Two-Factor Authentication Bypass

Vulnerability report for CVE-2026-14291, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-23

Last updated on: 2026-07-23

Assigner: WPScan

Description

The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without the one-time code and bypass enforced two-factor authentication for any account, including administrators. The affected two-factor module ships only in the premium build.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-23
Last Modified
2026-07-23
Generated
2026-07-23
AI Q&A
2026-07-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
security_ninja premium to 5.290 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Security Ninja Premium WordPress plugin before version 5.290. It allows an unauthenticated attacker who knows a user's password to bypass two-factor authentication (2FA) and gain full access to any account, including administrators. The flaw exists because the plugin fails to verify the second authentication factor in one of its 2FA code paths.

Detection Guidance

Check the installed version of the Security Ninja (Premium) plugin. If it is below 5.290, the system is vulnerable. This can be done by inspecting the plugin files or using WordPress admin panel to view the plugin version.

Impact Analysis

An attacker can exploit this to log in to any account by providing only the correct password, skipping the required one-time code. This grants full access to the compromised account, including administrative privileges. The attack is possible remotely without needing physical access to the system.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements under GDPR and HIPAA. It undermines authentication controls required by these regulations, potentially resulting in data breaches and legal penalties.

Mitigation Strategies

Update the Security Ninja (Premium) plugin to version 5.290 or later immediately. This version includes the fix for the 2FA bypass vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14291. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart