PT-2022-13578 · Siteground · Siteground Security Plugin

Chloe Chamberland

·

Published

2022-04-19

·

Updated

2024-01-11

·

CVE-2022-0993

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SiteGround Security plugin for WordPress versions up to, and including, 1.2.5
Description The issue allows unauthenticated users to log in as administrative users due to missing identity verification on the 2FA back-up code implementation that logs users in upon success.
Recommendations For versions up to, and including, 1.2.5, update to a version that includes the necessary identity verification for the 2FA back-up code implementation to prevent authentication bypass. As a temporary workaround, consider disabling the 2FA back-up code feature until a patch is available.

Exploit

Fix

Missing Authentication

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-0993

Affected Products

Siteground Security Plugin