CVE-2024-37881
The SiteGuard WP Plugin before version 1.7.7 allows users to customize the login page path as an alternative to the standard wp-login.php URL, but the redirect protection mechanism fails to account for the wp-register.php endpoint, creating an information disclosure vulnerability. An attacker could potentially exploit this gap to redirect users from the registration page and capture sensitive data. The flaw was identified by Yuuta Watanabe of STNet, Incorporated and coordinated through JPCERT/CC's early warning partnership program.
Based on public CVE data (MITRE/NVD).