SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-14291

HIGH · CVSS 7.5 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The security-ninja-premium WordPress plugin prior to version 5.290 is vulnerable due to improper verification of the second authentication factor, enabling an unauthenticated attacker with a user's password to bypass two-factor authentication entirely. This flaw poses a significant risk, particularly for administrator accounts, as it undermines the intended security of the authentication process. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of unauthorized access.

CVE
CVE-2026-14291
Severity
HIGH
CVSS
7.5
EPSS
0.33%
WordPress

Original NVD Description

The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without the one-time code and bypass enforced two-factor authentication for any account, including administrators. The affected two-factor module ships only in the premium build.