← WordPress Vulnerabilities
WordPress security by component

SiteGround Security

SiteGround Security provides WordPress tools for configuring site security, login protection, and security-related settings.

SiteGround Security (sg-security) is a WordPress plugin with 4 published CVE records in this archive. The latest tracked vulnerability was published Aug 31, 2026; the highest published CVSS base score is 8.1.

Plugin slug: sg-security

CVE-2026-82228: SiteGround Security permits unauthenticated two-factor authentication bypass

SiteGround Security through 1.6.6 permits an unauthenticated attacker to bypass its two-factor authentication protection under a higher-complexity condition. Successful exploitation can compromise the confidentiality, integrity and availability of the affected account and site.

PublishedAug 31, 2026
Known safe version1.6.7
Published vulnerabilities for sg-security
Safe version
Aug 31, 2026 CVE-2026-82228
SiteGround Security permits unauthenticated two-factor authentication bypass
SiteGround Security through 1.6.6 permits an unauthenticated attacker to bypass its two-factor authentication protection under a higher-complexity condition. Successful exploitation can compromise the confidentiality, integrity and availability of the affected account and site.
1.6.7
CVE8.1
NVDPending
Aug 06, 2026 CVE-2026-13342
Security Optimizer permits IP login-restriction bypass
Security Optimizer 1.5.8 through 1.6.4 incorrectly validates requests handled by its optional IP-based login restriction. An unauthenticated request outside the administrator's allowlist can bypass that gate and reach the WordPress login form. This defeats the configured IP restriction but does not bypass WordPress credentials. The crafted request property, header or parameter, route and validation function are not disclosed.
1.6.5
CVE5.3
NVDPending
Dec 16, 2025 CVE-2025-66121
SiteGround Security: A security weakness
SiteGround Security is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Nov 01, 2024 CVE-2024-38774
SiteGround Security: A security weakness
SiteGround Security is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending