8.1
CVE-2026-82228
- EPSS 0.23%
- Veröffentlicht 31.08.2026 20:30:55
- Zuletzt bearbeitet 01.09.2026 20:48:22
- Erkennungen
WordPress SiteGround Security plugin <= 1.6.6 - 2FA Bypass vulnerability
Security Optimizer – The All-In-One Protection Plugin <= 1.6.6 - 2-Factor Authentication Bypass
Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.
Mögliche Gegenmaßnahme
Security Optimizer – The All-In-One Protection Plugin: Update to version 1.6.7, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSiteGround
≫
Produkt
SiteGround Security
Default Statusunaffected
Version <=
1.6.6
Version
n/a
Status
affected
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Security Optimizer – The All-In-One Protection Plugin
Version
*-1.6.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.141 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| audit@patchstack.com | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-290 Authentication Bypass by Spoofing
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
https://patchstack.com/database/wordpress/plugin/sg-security/vulnerability/wordpress-siteground-security-plugin-1-6-6-2fa-bypass-vulnerability?_s_id=cve
https://www.wordfence.com/threat-intel/vulnerabilities/id/5ce8f128-78c6-4118-a178-0c163c55b07d