Two-Factor Authentication Bypass in Security Ninja Premium WordPress Plugin
CVE-2026-14291
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 23 July 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-14291?
The Security Ninja Premium WordPress plugin versions prior to 5.290 have a significant flaw in their two-factor authentication implementation. An unauthenticated attacker equipped with a user's password can bypass the required one-time code needed for authentication. This vulnerability compromises the integrity of two-factor authentication mechanisms, potentially allowing unauthorized access to user accounts, including those of administrators.
Affected Version(s)
security-ninja-premium 0 < 5.290
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.