Junglewise Threat Intelligence

CVE-2026-14291: Security Ninja Premium 2FA bypass via secnin_skip_2fa

CVE-2026-14291 · Severity: info · CVSS 8.1 · Published 2026-07-23

Executive brief

Security Ninja Premium, a WordPress plugin used to enhance website security, contains a flaw in its two-factor authentication (2FA) system. If an attacker already knows a user's password, they can bypass the second security layer entirely without needing the one-time code. This allows unauthorized access to any account, including administrator accounts, potentially leading to a full site takeover.

Technical details

An authentication bypass vulnerability exists in Security Ninja Premium versions prior to 5.290 due to an insecure AJAX action. The plugin exposes a 'secnin_skip_2fa' action in 'admin-ajax.php' that does not properly validate the completion of the second authentication factor. An unauthenticated attacker who has obtained a user's primary credentials can retrieve a temporary token from the initial login challenge and then use this AJAX action to finalize the session. This results in the issuance of a valid authentication cookie without the submission of a TOTP or OTP code. The vulnerability is fixed in version 5.290.

Affected products

  • Security Ninja Security Ninja Premium < 5.290

Timeline

  • 2026-07-02: disclosed: Initial public disclosure by WPScan
  • 2026-07-23: advisory: NVD publication date

References