cvedb.io
CVE-2026-14291
UNKNOWN · CVSS n/a
EPSS exploitation probability: 0%
Published 2026-07-23T07:16:32.397 · Last modified 2026-07-23T07:16:32.397

Summary

The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without the one-time code and bypass enforced two-factor authentication for any account, including administrators. The affected two-factor module ships only in the premium build.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.