Impact
The Security Ninja Premium WordPress plugin, in all releases before 5.290, fails to enforce the second authentication step in one of its two‑factor code paths. An attacker who knows a user’s password can complete the login process without providing the required one‑time code, thereby gaining authenticated access to any account, including administrators. This improper authentication flaw (CWE‑287) jeopardizes both the confidentiality and integrity of the site whenever user credentials are exposed or guessed.
Affected Systems
Any WordPress site that has the Security Ninja Premium plugin installed and running a version earlier than 5.290 is affected. The plugin’s premium module is the only build that ships the vulnerable two‑factor feature, and the exact vendor is listed as unknown:security‑ninja‑premium.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5 and an EPSS of less than 1%, indicating that active exploitation is currently considered unlikely but not impossible. It is not listed in the CISA KEV catalog, so there are no known public exploits at the time of this analysis. Exploitation requires knowledge of a user’s password but does not need any additional privileges or prior compromise. The likely attack vector is remote and unauthenticated through the normal WordPress login page; an attacker could obtain the password via phishing, brute‑force, or credential stuffing. The impact would be elevated privileges on the target site, potentially including administrative control. Administrators should not delay remediation because the ability to bypass two‑factor authentication threatens all sites running vulnerable versions.
OpenCVE Enrichment