SiteGround Security <= 1.2.5 - Authentication Bypass via 2FA Setup
CVE-2022-0992
What is CVE-2022-0992?
The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on initial 2FA set-up that allows unauthenticated and unauthorized users to configure 2FA for pending accounts. Upon successful configuration, the attacker is logged in as that user without access to a username/password pair which is the expected first form of authentication. This affects versions up to, and including, 1.2.5.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Security Optimizer β The All-In-One WordPress Protection Plugin * <= 1.2.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
