CVE · Medium

CVE-2025-66121 — Security Optimizer – The All-In-One Protection Plugin [sg-security] < 1.5.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-66121 Security Optimizer – The All-In-One Protection Plugin [sg-security] < 1.5.9 Missing Authorization Medium 5.3 < 1.5.9 1.5.9 2025-11-30

CVE-2025-66121

A security flaw exists in the SiteGround Security plugin for WordPress, where a critical oversight has been identified in the authorization process of certain functions within the software. Specifically, versions up to and including 1.5.8 lack adequate checks on user permissions, allowing malicious actors without authentication to execute unauthorized actions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.