Extension WordPress
Vulnérabilités Secure Copy Content Protection and Content Locking
Cette page rassemble les failles publiées pour Secure Copy Content Protection and Content Locking, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Secure Copy Content Protection and Content Locking
16 fiches
Secure Copy Content Protection and Content Locking <= 5.0.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute
The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ays_block' shortcode in all versions up to, and including, 5.0.1 due to insufficient input sanitization and output escaping…
*-5.0.1
5.0.2
24/02/2026
Secure Copy Content Protection and Content Locking <= 4.9.8 – Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For Header
The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' HTTP header in all versions up to, and including, 4.9.8 due to insufficient input sanitization and output escaping.…
*-4.9.8
4.9.9
12/02/2026
Secure Copy Content Protection and Content Locking <= 5.0.0 – Missing Authorization
The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.0.0. This makes it possible for…
*-5.0.0
5.0.1
08/02/2026
Secure Copy Content Protection and Content Locking <= 4.9.2 – Unauthenticated Sensitive Information Exposure via Exposed CSV Export File
The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to sensitive information exposure due to storage of exported CSV files in a publicly accessible directory with predictable filenames in all versions up to, and…
*-4.9.2
4.9.3
11/12/2025
Secure Copy Content Protection and Content Locking <= 4.9.2 – Cross-Site Request Forgery to Data Export
The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.9.2. This is due to missing nonce validation on the 'ays_sccp_results_export_file' AJAX action. This…
*-4.9.2
4.9.3
11/12/2025
Secure Copy Content Protection and Content Locking <= 4.5.5 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-4.5.5
4.5.6
04/04/2025
Secure Copy Content Protection and Content Locking <= 4.4.3 – Unauthenticated Stored Cross-Site Scripting
The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping. This makes it possible for…
*-4.4.3
4.4.5
01/04/2025
Secure Copy Content Protection and Content Locking <= 4.4.7 – Missing Authorization to Unauthenticated User Email Retrieval via ays_sccp_reports_user_search Function
The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_sccp_reports_user_search() function in all versions up to, and including, 4.4.7. This makes…
*-4.4.7
4.4.8
28/02/2025
Secure Copy Content Protection and Content Locking <= 4.2.3 – Reflected Cross-Site Scripting
The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.2.3 due to insufficient input sanitization and output escaping. This makes it possible for…
*-4.2.3
4.2.4
25/09/2024
Secure Copy Content Protection and Content Locking <= 4.1.6 – Authenticated (Admin+) Stored Cross-Site Scripting
The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Custom class for tooltip container" field in all versions up to, and including, 4.1.6 due to insufficient input sanitization…
*-4.1.6
4.1.7
13/08/2024
Secure Copy Content Protection and Content Locking <= 4.1.6 – Authenticated (Admin+) Stored Cross-Site Scripting
The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS setting in all versions up to, and including, 4.1.6 due to insufficient input sanitization and output escaping.…
*-4.1.6
4.1.7
13/08/2024
Secure Copy Content Protection and Content Locking <= 4.0.8 – Authenticated (Admin+) Stored Cross-Site Scripting
The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.0.8 due to insufficient input sanitization and output escaping. This makes…
*-4.0.8
4.0.9
20/06/2024
Secure Copy Content Protection and Content Locking <= 3.9.0 – Missing Authorization
The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_sccp_option function in versions up to, and including, 3.9.0. This makes it…
*-3.9.0
3.9.1
25/04/2024
Secure Copy Content Protection and Content Locking <= 3.7.1 – Missing Authorization
The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 3.7.1. This makes it possible for authenticated attackers, with subscriber-level…
*-3.7.1
3.7.2
22/04/2024
Secure Copy Content Protection and Content Locking <= 2.8.1 – Unauthenticated SQL Injection
The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading…
*-2.8.1
2.8.2
08/11/2021
Secure Copy Content Protection and Content Locking <= 2.6.6 – SQL Injection
The get_reports() function in the Secure Copy Content Protection and Content Locking WordPress plugin before 2.6.7 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading…
[*, 2.6.7)
2.6.7
29/06/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.