SiteGround Security <= 1.2.5 - Authorization Weakness to Authentication Bypass
CVE-2022-0993
8.1HIGH
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 19 April 2022
Summary
The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on the 2FA back-up code implementation that logs users in upon success. This affects versions up to, and including, 1.2.5.
Affected Version(s)
Security Optimizer – The All-In-One WordPress Protection Plugin * <= 1.2.5
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Chloe Chamberland