Beta

Report

SiteGround Security <= 1.2.5 is vulnerable to Authorization Weakness to Authentication Bypass via 2-Factor Authentication Back-up Codes vulnerability

Unauthenticated
Published
2022-04-06

The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on the 2FA back-up code implementation that logs users in upon success. This affects versions up to, and including, 1.2.5.

CVSS

Score:8.1

Severity:High

Version: 1.2.5

There is a patch available in v1.2.6 and we strongly recommend you update to this version as soon as possible.