Back to overview

CVE-2026-14291

Description
The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without the one-time code and bypass enforced two-factor authentication for any account, including administrators. The affected two-factor module ships only in the premium build.

Metadata

CVE ID
CVE-2026-14291
State
PUBLISHED
Assigner
WPScan
Reserved
2026-07-01 08:48 UTC
Published
2026-07-23 06:00 UTC
Last updated
2026-07-23 06:00 UTC
Vendor / Product
Unknown / security-ninja-premium
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
Unknown security-ninja-premium 0 < 5.290
Weakness (CWE)
CWESourceDescription
cna CWE-287 Improper Authentication
Back to overview