Products
SiteGuard WP Plugin
- before 1.7.7
Source
vultures@jpcert.or.jp
Tags
CVE-2024-37881 details
Published : June 19, 2024, 7:15 a.m.
Last Modified : June 19, 2024, 7:15 a.m.
Last Modified : June 19, 2024, 7:15 a.m.
Description
SiteGuard WP Plugin provides a functionality to customize the path to the login page wp-login.php and implements a measure to avoid redirection from other URLs. However, SiteGuard WP Plugin versions prior to 1.7.7 missed to implement a measure to avoid redirection from wp-register.php. As a result, the customized path to the login page may be exposed.
CVSS Score
1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|
References
URL | Source |
---|---|
https://jvn.jp/en/jp/JVN60331535/ | vultures@jpcert.or.jp |
https://plugins.trac.wordpress.org/changeset/3094238/siteguard/trunk/classes/siteguard-rename-login.php?old=2888160&old_path=siteguard%2Ftrunk%2Fclasses%2Fsiteguard-rename-login.php | vultures@jpcert.or.jp |
https://www.jp-secure.com/siteguard_wp_plugin_en/vuls/WPV2024001_en.html | vultures@jpcert.or.jp |
This website uses the NVD API, but is not approved or certified by it.