PT-2022-13578 · Siteground · Siteground Security Plugin
Chloe Chamberland
·
Published
2022-04-19
·
Updated
2024-01-11
·
CVE-2022-0993
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SiteGround Security plugin for WordPress versions up to, and including, 1.2.5
Description
The issue allows unauthenticated users to log in as administrative users due to missing identity verification on the 2FA back-up code implementation that logs users in upon success.
Recommendations
For versions up to, and including, 1.2.5, update to a version that includes the necessary identity verification for the 2FA back-up code implementation to prevent authentication bypass. As a temporary workaround, consider disabling the 2FA back-up code feature until a patch is available.
Exploit
Fix
Missing Authentication
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Siteground Security Plugin