WordPress security by component
SiteGround Security
Plugin description
SiteGround Security provides WordPress tools for configuring site security, login protection, and security-related settings.
SiteGround Security (sg-security) is a WordPress plugin with 4 published CVE records in this archive. The latest tracked vulnerability was published Aug 31, 2026; the highest published CVSS base score is 8.1.
Plugin slug:
sg-securityLatest vulnerability
CVE-2026-82228: SiteGround Security permits unauthenticated two-factor authentication bypass
SiteGround Security through 1.6.6 permits an unauthenticated attacker to bypass its two-factor authentication protection under a higher-complexity condition. Successful exploitation can compromise the confidentiality, integrity and availability of the affected account and site.
| Safe version |
|
||
|---|---|---|---|
| Aug 31, 2026 |
CVE-2026-82228
SiteGround Security permits unauthenticated two-factor authentication bypass
SiteGround Security through 1.6.6 permits an unauthenticated attacker to bypass its two-factor authentication protection under a higher-complexity condition. Successful exploitation can compromise the confidentiality, integrity and availability of the affected account and site.
|
1.6.7 |
CVE8.1
NVDPending
|
| Aug 06, 2026 |
CVE-2026-13342
Security Optimizer permits IP login-restriction bypass
Security Optimizer 1.5.8 through 1.6.4 incorrectly validates requests handled by its optional IP-based login restriction. An unauthenticated request outside the administrator's allowlist can bypass that gate and reach the WordPress login form. This defeats the configured IP restriction but does not bypass WordPress credentials. The crafted request property, header or parameter, route and validation function are not disclosed.
|
1.6.5 |
CVE5.3
NVDPending
|
| Dec 16, 2025 |
CVE-2025-66121
SiteGround Security: A security weakness
SiteGround Security is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Nov 01, 2024 |
CVE-2024-38774
SiteGround Security: A security weakness
SiteGround Security is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|