CVE-2019-25217
The SiteGround Optimizer plugin through version 5.0.12 contains an authorization bypass vulnerability in its /switch-php REST API endpoint that fails to properly validate access permissions on the switch_php function. This flaw allows unauthenticated attackers to include and execute arbitrary files from the server, enabling them to run malicious PHP code and potentially compromise the entire WordPress installation. The vulnerability can be exploited to bypass security restrictions, steal sensitive information, or execute code through uploaded files that would normally be considered safe, such as images.
Based on public CVE data (MITRE/NVD).