CVE-2022-0992
SiteGround Security <= 1.2.5 - Authentication Bypass via 2FA Setup
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on initial 2FA set-up that allows unauthenticated and unauthorized users to configure 2FA for pending accounts. Upon successful configuration, the attacker is logged in as that user without access to a username/password pair which is the expected first form of authentication. This affects versions up to, and including, 1.2.5.
El plugin de seguridad de SiteGround para WordPress es vulnerable a una omisión de autenticación que permite a usuarios no autenticados iniciar sesión como usuarios administrativos debido a una falta de verificación de identidad en la configuración inicial de 2FA que permite a usuarios no autenticados y no autorizados configurar 2FA para cuentas pendientes. Una vez configurado con éxito, el atacante es registrado como ese usuario sin acceso a un par de nombre de usuario/contraseña que es la primera forma de autenticación esperada. Esto afecta a versiones hasta la 1.2.5 incluyéndola
WordPress SiteGround Security plugin versions 1.2.5 and below suffer from an authentication bypass vulnerability as well as an authorization weakness in versions 1.2.4 and below.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-03-16 CVE Reserved
- 2022-04-06 CVE Published
- 2022-04-08 First Exploit
- 2024-08-02 CVE Updated
- 2025-01-02 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-288: Authentication Bypass Using an Alternate Path or Channel
- CWE-306: Missing Authentication for Critical Function
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://www.wordfence.com/threat-intel/vulnerabilities/id/6e5c6bf7-a653-4571-9566-574d2bb35c4f?source=cve | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/166642 | 2022-04-08 | |
https://www.wordfence.com/blog/2022/04/critical-authentication-bypass-vulnerability-patched-in-siteground-security-plugin | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://plugins.trac.wordpress.org/changeset/2706302 | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siteground Search vendor "Siteground" | Security Optimizer Search vendor "Siteground" for product "Security Optimizer" | < 1.2.6 Search vendor "Siteground" for product "Security Optimizer" and version " < 1.2.6" | wordpress |
Affected
|