Description
The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on the 2FA back-up code implementation that logs users in upon success. This affects versions up to, and including, 1.2.5.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-15986 | The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on the 2FA back-up code implementation that logs users in upon success. This affects versions up to, and including, 1.2.5. |
References
History
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | SiteGround Security <= 1.2.5 - Authorization Weakness to Authentication Bypass | |
| Weaknesses | CWE-285 |
Tue, 15 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:06:18.657Z
Reserved: 2022-03-16T00:00:00.000Z
Link: CVE-2022-0993
Updated: 2024-08-02T23:47:43.246Z
Status : Modified
Published: 2022-04-19T21:15:13.683
Modified: 2026-04-08T18:17:21.967
Link: CVE-2022-0993
No data.
OpenCVE Enrichment
No data.
EUVD