CVE-2026-82228
largeUnauthenticated Authentication Bypass in SiteGround Security WordPress Plugin
CVE-2026-82228 is an unauthenticated authentication bypass (CWE-290) in the SiteGround Security WordPress plugin, affecting all versions up to and including 1.6.6. An attacker can trigger the flaw remotely over the network by sending a crafted request that slips past the plugin's authentication check, and the high attack-complexity score (AC:H) indicates exploitation depends on non-trivial conditions. A successful bypass grants access to functionality normally gated by the plugin's checks, with CVSS scoring high impact to confidentiality, integrity, and availability. Any WordPress site running SiteGround Security 1.6.6 or earlier is affected. Exploitation has not been observed: there is no public proof of concept, the flaw is not in CISA's KEV, and EPSS estimates only a ~0.2% chance of exploitation within 30 days.
What to do: Update SiteGround Security to the latest patched release (any version above 1.6.6) as soon as it is available, and verify the installed version on the WordPress Plugins page. Until patched, monitor logs for anomalous unauthenticated requests to the site and consider a WAF rule or temporary access restriction as mitigation. No public PoC exists yet; monitor advisories from SiteGround and Patchstack for the confirmed fixed version.
| SiteGround Security (WordPress plugin) | <= 1.6.6 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-290
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.