What is CVE-2026-14291?
This vulnerability affects the 'security-ninja-premium' WordPress plugin prior to version 5.290. It fails to verify the second authentication factor in one of its 2FA code paths, allowing an unauthenticated attacker who knows a user's password to bypass the one-time code. Immediate updating to version 5.290 or later is strongly recommended.
Azərbaycanca: Bu boşluq "security-ninja-premium" WordPress plaginin 5.290-dan əvvəlki versiyalarına təsir edir. İki faktorlu autentifikasiyanın (2FA) bir kod yolunda ikinci addımın yoxlanılmaması səbəbindən, autentifikasiya olunmamış şəxs istifadəçi parolunu bildiyi təqdirdə birdəfəlik kod olmadan hesaba daxil ola bilər. Plaginin 5.290 və ya daha yeni versiyasına təcili yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which versions of the security-ninja-premium plugin are affected by CVE-2026-14291?
This vulnerability affects versions of the plugin prior to 5.290.
What must an attacker know to successfully exploit CVE-2026-14291?
The attacker must know the user's password to bypass the 2FA.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.