CVE · Medium

CVE-2024-37881 — SiteGuard WP Plugin [siteguard] < 1.7.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-37881 SiteGuard WP Plugin [siteguard] < 1.7.7 Insertion of Sensitive Information Into Sent Data Medium 5.3 < 1.7.7 1.7.7 2024-06-19

CVE-2024-37881

The SiteGuard WP Plugin before version 1.7.7 allows users to customize the login page path as an alternative to the standard wp-login.php URL, but the redirect protection mechanism fails to account for the wp-register.php endpoint, creating an information disclosure vulnerability. An attacker could potentially exploit this gap to redirect users from the registration page and capture sensitive data. The flaw was identified by Yuuta Watanabe of STNet, Incorporated and coordinated through JPCERT/CC's early warning partnership program.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.