Impact
The vulnerability is a missing authorization flaw that permits attackers to bypass access controls and gain unauthorized privileges on a WordPress site using the SiteGround Security plugin. Once compromised, an attacker could view, modify, or delete site content and potentially execute administrative actions beyond their intended scope. The weakness is a classic authorization failure, mapped to CWE‑862.
Affected Systems
Affected products are the SiteGround Security plugin for WordPress, versions from the earliest release up through and including 1.5.8. Any WordPress installation that has not upgraded past 1.5.8 remains vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and an EPSS of less than 1% shows a very low predicted exploitation probability. The vulnerability is not currently listed in CISA KEV. The likely attack vector is through web-based requests to plugin endpoints, where a user without proper privileges can exploit incorrect access control settings. If the plugin least‑privilege restrictions are not properly enforced, remote attackers could elevate their privileges or perform unauthorized site operations.
OpenCVE Enrichment