CVE-2026-82228: WordPress SiteGround Security plugin <= 1.6.6 - 2FA Bypass vulnerability
Published Aug 31, 2026
·Updated
Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.
Affected Software
1 affected component
WordPress SiteGround Security plugin<=1.6.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress SiteGround Security pluginto a version that resolves this vulnerability.Fixed in 1.6.7
Event History
Aug 31, 2026
CVE Published
via MITRE·08:30 PM
Data Sourced
via MITRE·08:30 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Does an attacker need an account or user interaction to exploit this issue?
No. The vulnerability is rated with no privileges required and no user interaction required, so exploitation does not depend on an existing WordPress account or victim action.
2
Is this exposure limited to local access?
No. The attack vector is network-based, meaning a reachable affected site could be targeted remotely. The attack complexity is rated high.
3
What could be affected if exploitation succeeds?
The severity vector indicates high potential impact to confidentiality, integrity, and availability.