Description
The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without the one-time code and bypass enforced two-factor authentication for any account, including administrators. The affected two-factor module ships only in the premium build.
Published: 2026-07-23
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Security Ninja Premium WordPress plugin, in all releases before 5.290, fails to enforce the second authentication step in one of its two‑factor code paths. An attacker who knows a user’s password can complete the login process without providing the required one‑time code, thereby gaining authenticated access to any account, including administrators. This improper authentication flaw (CWE‑287) jeopardizes both the confidentiality and integrity of the site whenever user credentials are exposed or guessed.

Affected Systems

Any WordPress site that has the Security Ninja Premium plugin installed and running a version earlier than 5.290 is affected. The plugin’s premium module is the only build that ships the vulnerable two‑factor feature, and the exact vendor is listed as unknown:security‑ninja‑premium.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.5 and an EPSS of less than 1%, indicating that active exploitation is currently considered unlikely but not impossible. It is not listed in the CISA KEV catalog, so there are no known public exploits at the time of this analysis. Exploitation requires knowledge of a user’s password but does not need any additional privileges or prior compromise. The likely attack vector is remote and unauthenticated through the normal WordPress login page; an attacker could obtain the password via phishing, brute‑force, or credential stuffing. The impact would be elevated privileges on the target site, potentially including administrative control. Administrators should not delay remediation because the ability to bypass two‑factor authentication threatens all sites running vulnerable versions.

Generated by OpenCVE AI on August 3, 2026 at 22:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Security Ninja Premium plugin to version 5.290 or later to enforce the second authentication factor correctly.
  • If upgrading immediately is infeasible, disable the insecure two‑factor bypass by configuring the plugin settings or editing the source to remove the secnin_skip_2fa path.
  • If neither upgrading nor disabling is possible, temporarily replace or supplement the plugin with a trusted two‑factor authentication solution to maintain security until the issue is resolved.

Generated by OpenCVE AI on August 3, 2026 at 22:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Description The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without the one-time code and bypass enforced two-factor authentication for any account, including administrators. The affected two-factor module ships only in the premium build.
Title Security Ninja (Premium) < 5.290 - Two-Factor Authentication Bypass via secnin_skip_2fa
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-23T14:10:42.101Z

Reserved: 2026-07-01T08:48:39.322Z

Link: CVE-2026-14291

cve-icon Vulnrichment

Updated: 2026-07-23T14:10:36.716Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T07:16:32.397

Modified: 2026-07-23T15:16:53.917

Link: CVE-2026-14291

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T23:00:04Z

Weaknesses