CVE-2022-0993
SiteGround Security <= 1.2.5 - Authorization Weakness to Authentication Bypass
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on the 2FA back-up code implementation that logs users in upon success. This affects versions up to, and including, 1.2.5.
El plugin de seguridad de SiteGround para WordPress es vulnerable a una omisión de autenticación que permite a usuarios no autenticados iniciar sesión como usuarios administrativos debido a una falta de verificación de identidad en la implementación del código de respaldo 2FA que inicia la sesión de los usuarios en caso de éxito. Esto afecta a las versiones hasta la 1.2.5 incluyéndola
WordPress SiteGround Security plugin versions 1.2.5 and below suffer from an authentication bypass vulnerability as well as an authorization weakness in versions 1.2.4 and below.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2022-03-16 CVE Reserved
- 2022-04-07 CVE Published
- 2022-04-08 First Exploit
- 2024-10-15 CVE Updated
- 2025-01-02 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-285: Improper Authorization
- CWE-306: Missing Authentication for Critical Function
CAPEC
References (4)
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/166642 | 2022-04-08 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://plugins.trac.wordpress.org/changeset/2706302 | 2024-01-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siteground Search vendor "Siteground" | Siteground Security Search vendor "Siteground" for product "Siteground Security" | <= 1.2.5 Search vendor "Siteground" for product "Siteground Security" and version " <= 1.2.5" | wordpress |
Affected
|