ZeroHour

CVE-2026-82228

large

Unauthenticated Authentication Bypass in SiteGround Security WordPress Plugin

CVSS 3.1
8.1 high
EPSS
<1%p14
Published
()
Modified
AI analysis

CVE-2026-82228 is an unauthenticated authentication bypass (CWE-290) in the SiteGround Security WordPress plugin, affecting all versions up to and including 1.6.6. An attacker can trigger the flaw remotely over the network by sending a crafted request that slips past the plugin's authentication check, and the high attack-complexity score (AC:H) indicates exploitation depends on non-trivial conditions. A successful bypass grants access to functionality normally gated by the plugin's checks, with CVSS scoring high impact to confidentiality, integrity, and availability. Any WordPress site running SiteGround Security 1.6.6 or earlier is affected. Exploitation has not been observed: there is no public proof of concept, the flaw is not in CISA's KEV, and EPSS estimates only a ~0.2% chance of exploitation within 30 days.

What to do: Update SiteGround Security to the latest patched release (any version above 1.6.6) as soon as it is available, and verify the installed version on the WordPress Plugins page. Until patched, monitor logs for anomalous unauthenticated requests to the site and consider a WAF rule or temporary access restriction as mitigation. No public PoC exists yet; monitor advisories from SiteGround and Patchstack for the confirmed fixed version.

Affected
SiteGround Security (WordPress plugin)<= 1.6.6
Estimated exposure
large≈700,000+ sites (hundreds of thousands of active installs per WordPress.org) — The estimate is based on the plugin's publicly reported WordPress.org active-install count, which is in the hundreds of thousands; all installs running 1.6.6 or earlier are plausibly exposed until patched.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.

Ecosystems
WordPress
Weakness
CWE-290
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.