Executive brief
SiteGround Security is a WordPress plugin that provides security hardening and two-factor authentication (2FA) protection for WordPress sites. An unauthenticated attacker can bypass the plugin's security checks, including 2FA protections, allowing unauthorized access to affected WordPress installations without proper credentials or second-factor verification.
Technical details
The vulnerability is an authentication bypass (OWASP A4: Insecure Design) in SiteGround Security plugin versions 1.6.6 and earlier. The flaw allows attackers to circumvent security checks and 2FA mechanisms without authentication or user interaction, affecting all unpatched installations. The plugin's 2FA bypass enables attackers to gain direct access to WordPress administrative or user accounts. A patch is available in version 1.6.7 and later. Given the high CVSS score (8.1) and the nature of the vulnerability, mass-exploitation campaigns are anticipated.
Affected products
- SiteGround Security <= 1.6.6
Timeline
- 2026-08-28: disclosed
- 2026-08-31: advisory
- 2026-08-28: patched: Version 1.6.7 contains the fix