CVE-2026-14291 PUBLISHED

Security Ninja (Premium) < 5.290 - Two-Factor Authentication Bypass via secnin_skip_2fa

Assigner: WPScan
Reserved: 01.07.2026 Published: 23.07.2026 Updated: 23.07.2026

The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without the one-time code and bypass enforced two-factor authentication for any account, including administrators. The affected two-factor module ships only in the premium build.

Product Status

Vendor Unknown
Product security-ninja-premium
Versions Default: unaffected
  • affected from 0 to 5.290 (excl.)

Credits

  • Adam Clinch finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE