CVE-2026-14291: WordPress Security Ninja Premium 2FA Authentication Bypass
ID: f00315d0-253c-5bb9-a305-95cf8e4f4c4c
STIX ID: report--f00315d0-253c-5bb9-a305-95cf8e4f4c4c
Feed Name: CosmicBytez Labs
Threat Score
**CVE-2026-14291 — Security Ninja Premium 2FA bypass:** An unauthenticated attacker who knows a user's password can bypass two-factor authentication via the secnin_skip_2fa parameter in Security Ninja Premium versions prior to 5.290; organizations should update to 5.290 immediately, audit recent logins, rotate privileged credentials, and apply mitigations (disable 2FA temporarily, restrict wp-login.php, enable account lockout) if patching cannot be done right away.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
