CVE-2024-37881 Information

Description

SiteGuard WP Plugin provides a functionality to customize the path to the login page wp-login.php and implements a measure to avoid redirection from other URLs. However SiteGuard WP Plugin versions prior to 1.7.7 missed to implement a measure to avoid redirection from wp-register.php. As a result the customized path to the login page may be exposed.

Reference

https://www.jp-secure.com/siteguard_wp_plugin_en/vuls/WPV2024001_en.html https://plugins.trac.wordpress.org/changeset/3094238/siteguard/trunk/classes/siteguard-rename-login.php?old=2888160&old_path=siteguard%2Ftrunk%2Fclasses%2Fsiteguard-rename-login.php https://jvn.jp/en/jp/JVN60331535/

Share on: