CyberRota Analysis
AI-GeneratedThe security-ninja-premium WordPress plugin prior to version 5.290 is vulnerable due to improper verification of the second authentication factor, enabling an unauthenticated attacker with a user's password to bypass two-factor authentication entirely. This flaw poses a significant risk, particularly for administrator accounts, as it undermines the intended security of the authentication process. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of unauthorized access.
Original NVD Description
The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without the one-time code and bypass enforced two-factor authentication for any account, including administrators. The affected two-factor module ships only in the premium build.