CVE-2022-0993: SiteGround Security <= 1.2.5 - Authorization Weakness to Authentication Bypass
The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on the 2FA back-up code implementation that logs users in upon success. This affects versions up to, and including, 1.2.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-0993?
CVE-2022-0993 is classified as a critical vulnerability due to the potential for unauthenticated access to administrative accounts.
How do I fix CVE-2022-0993?
To fix CVE-2022-0993, update the SiteGround Security plugin to version 1.2.6 or later.
Who is affected by CVE-2022-0993?
CVE-2022-0993 affects users of the SiteGround Security plugin for WordPress versions up to and including 1.2.5.
What kind of attack does CVE-2022-0993 enable?
CVE-2022-0993 allows an attacker to bypass authentication and gain administrative access without proper credentials.
Is there any workaround for CVE-2022-0993?
There is no effective workaround for CVE-2022-0993; updating the plugin is the only secure option.