SiteGuard WP Plugin

SiteGuard WP Plugin has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 3 are fixed as of September 2026. Their average CVSS score is 5.9, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high. 2026 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 1 of the records (33%). Other recurring categories include Missing Authorization, Protection Mechanism Failure.

Every one of the 3 issues recorded for SiteGuard WP Plugin has a vendor fix available, so running the current release closes all known holes.

3 independent researchers contributed these findings, one record each. SiteGuard WP Plugin is installed on roughly 600,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
5.9/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all SiteGuard WP Plugin vulnerabilities before they are exploited.

Highest severity on recordCVSS 7.2CVE-2026-61982

SiteGuard WP Plugin <= 1.8.6 - Unauthenticated Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

3 records
SiteGuard WP Plugin banner
Latestv1.8.9

SiteGuard WP Plugin

jp-secure

Author

jp-secure

4.3(15)
86/100
Last Updated
2026-08-19 (25d ago)
Active Installs
600,000+
Downloads
7,428,897
Requires WP
6.0+
Requires PHP
0+
Tested up to
WP 7.1
Created
2014-10-22 (12y ago)

SiteGuard WP Plugin helps protect WordPress sites by strengthening login and admin-area security. It helps reduce brute-force login attacks, password list attacks, comment spam, and unauthorized access to /wp-admin/. Main Features Admin Page IP Filter: Restricts wp-admin access to IP addresses that have successfully logged in. Rename Login: Changes the URL of the login page from wp-login.php to a custom path. CAPTCHA: Adds CAPTCHA to login, comment, password reset, and user registration forms. Login Lock: Temporarily locks out IP addresses after repeated failed login attempts. Login Alert: Sends email notifications when users log in. Fail Once: Intentionally rejects the first valid login attempt and requires the user to try again shortly after. Protect XML-RPC: Disables pingbacks or all XML-RPC access to help prevent abuse. Block Author Query: Helps prevent username leakage through /?author=<number> requests. Update Notifications: Sends email notifications when updates are available for WordPress core, plugins, or themes. WAF Tuning Support: Creates exclusion rules to help prevent false positives when SiteGuard Server Edition WAF is installed. Requirements and Compatibility WordPress multisite is not supported. Apache 1.3, Apache 2.x, and Nginx are supported. Rename Login cannot be combined with a login page URL change feature in another plugin. Enable it in only one plugin; using both can leave two login URLs available, or stop the login page from loading. CAPTCHA requires the PHP extensions mbstring and gd. WAF Tuning Support requires SiteGuard Server Edition on Apache. Documentation Documentation, FAQs, and more details are available in English and Japanese. Translations This plugin is translated by the community. We appreciate your help with translations on the WordPress translation platform.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C