Impact
SiteGuard WP Plugin versions 1.8.6 and earlier are vulnerable to unauthenticated cross‑site scripting. An attacker can inject malicious JavaScript through the plugin’s input fields or URL parameters, causing the code to execute in the browsers of any site visitor and potentially enabling unauthorized actions against site users.
Affected Systems
Any WordPress installation running jp‑secure SiteGuard WP Plugin 1.8.6 or earlier. The fix requires upgrading to version 1.8.7 or later.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Because the flaw is unauthenticated, any visitor to a vulnerable site can craft a malicious request, making exploitation straightforward for attackers with minimal resources.
OpenCVE Enrichment