CVE-2026-14291
Security Ninja (Premium) < 5.290 - Two-Factor Authentication Bypass via secnin_skip_2fa
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without the one-time code and bypass enforced two-factor authentication for any account, including administrators. The affected two-factor module ships only in the premium build.
| Vendor | unknown |
| Product | security-ninja-premium |
| Published | Jul 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown security-ninja-premium
Be the first to know when new unknown vulnerabilities affecting unknown security-ninja-premium are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / security-ninja-premium
0 < 5.290
References
Credits
Adam Clinch WPScan