Impact
The vulnerability in the SiteGround Security plugin allows an attacker to bypass the two‑factor authentication mechanism without any prior credentials, effectively granting unrestricted access to the WordPress site's administrative functions. This flaw can lead to full site compromise, data theft, or further exploitation within the web application.
Affected Systems
SiteGround Security plugin for WordPress, releases version 1.6.6 and earlier. The issue is fixed starting with version 1.6.7 and later.
Risk and Exploitability
The CVSS score of 8.1 classifies the issue as high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw remotely via the plugin’s authentication endpoints, requiring no existing credentials. The combination of a high impact and a remotely exploitable vector presents a significant threat to affected WordPress sites.
OpenCVE Enrichment