Extension WordPress

Vulnérabilités Secure Copy Content Protection and Content Locking

Cette page rassemble les failles publiées pour Secure Copy Content Protection and Content Locking, leurs plages de versions affectées et les correctifs signalés dans la base locale.

16Vulnérabilités
1Critiques
16Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Secure Copy Content Protection and Content Locking

16 fiches

CVE-2026-2367 Moyenne · 6,4
Secure Copy Content Protection and Content Locking

Secure Copy Content Protection and Content Locking <= 5.0.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ays_block' shortcode in all versions up to, and including, 5.0.1 due to insufficient input sanitization and output escaping…

Versions affectées

*-5.0.1

Correctif

5.0.2

Publication

24/02/2026

CVE-2026-1320 Élevée · 7,2
Secure Copy Content Protection and Content Locking

Secure Copy Content Protection and Content Locking <= 4.9.8 – Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For Header

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' HTTP header in all versions up to, and including, 4.9.8 due to insufficient input sanitization and output escaping.…

Versions affectées

*-4.9.8

Correctif

4.9.9

Publication

12/02/2026

CVE-2025-14442 Moyenne · 5,3
Secure Copy Content Protection and Content Locking

Secure Copy Content Protection and Content Locking <= 4.9.2 – Unauthenticated Sensitive Information Exposure via Exposed CSV Export File

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to sensitive information exposure due to storage of exported CSV files in a publicly accessible directory with predictable filenames in all versions up to, and…

Versions affectées

*-4.9.2

Correctif

4.9.3

Publication

11/12/2025

CVE-2025-14159 Moyenne · 4,3
Secure Copy Content Protection and Content Locking

Secure Copy Content Protection and Content Locking <= 4.9.2 – Cross-Site Request Forgery to Data Export

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.9.2. This is due to missing nonce validation on the 'ays_sccp_results_export_file' AJAX action. This…

Versions affectées

*-4.9.2

Correctif

4.9.3

Publication

11/12/2025

CVE-2025-32133 Moyenne · 4,4
Secure Copy Content Protection and Content Locking

Secure Copy Content Protection and Content Locking <= 4.5.5 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

*-4.5.5

Correctif

4.5.6

Publication

04/04/2025

CVE-2025-30905 Moyenne · 6,1
Secure Copy Content Protection and Content Locking

Secure Copy Content Protection and Content Locking <= 4.4.3 – Unauthenticated Stored Cross-Site Scripting

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-4.4.3

Correctif

4.4.5

Publication

01/04/2025

CVE-2025-1404 Moyenne · 5,3
Secure Copy Content Protection and Content Locking

Secure Copy Content Protection and Content Locking <= 4.4.7 – Missing Authorization to Unauthenticated User Email Retrieval via ays_sccp_reports_user_search Function

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_sccp_reports_user_search() function in all versions up to, and including, 4.4.7. This makes…

Versions affectées

*-4.4.7

Correctif

4.4.8

Publication

28/02/2025

CVE-2024-47306 Moyenne · 6,1
Secure Copy Content Protection and Content Locking

Secure Copy Content Protection and Content Locking <= 4.2.3 – Reflected Cross-Site Scripting

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.2.3 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-4.2.3

Correctif

4.2.4

Publication

25/09/2024

CVE-2024-6889 Moyenne · 4,4
Secure Copy Content Protection and Content Locking

Secure Copy Content Protection and Content Locking <= 4.1.6 – Authenticated (Admin+) Stored Cross-Site Scripting

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Custom class for tooltip container" field in all versions up to, and including, 4.1.6 due to insufficient input sanitization…

Versions affectées

*-4.1.6

Correctif

4.1.7

Publication

13/08/2024

CVE-2024-6888 Moyenne · 4,4
Secure Copy Content Protection and Content Locking

Secure Copy Content Protection and Content Locking <= 4.1.6 – Authenticated (Admin+) Stored Cross-Site Scripting

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS setting in all versions up to, and including, 4.1.6 due to insufficient input sanitization and output escaping.…

Versions affectées

*-4.1.6

Correctif

4.1.7

Publication

13/08/2024

CVE-2024-6138 Moyenne · 4,4
Secure Copy Content Protection and Content Locking

Secure Copy Content Protection and Content Locking <= 4.0.8 – Authenticated (Admin+) Stored Cross-Site Scripting

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.0.8 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-4.0.8

Correctif

4.0.9

Publication

20/06/2024

CVE-2024-33587 Moyenne · 5,3
Secure Copy Content Protection and Content Locking

Secure Copy Content Protection and Content Locking <= 3.9.0 – Missing Authorization

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_sccp_option function in versions up to, and including, 3.9.0. This makes it…

Versions affectées

*-3.9.0

Correctif

3.9.1

Publication

25/04/2024

CVE-2024-32787 Moyenne · 4,3
Secure Copy Content Protection and Content Locking

Secure Copy Content Protection and Content Locking <= 3.7.1 – Missing Authorization

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 3.7.1. This makes it possible for authenticated attackers, with subscriber-level…

Versions affectées

*-3.7.1

Correctif

3.7.2

Publication

22/04/2024

CVE-2021-24931 Critique · 9,8
Secure Copy Content Protection and Content Locking

Secure Copy Content Protection and Content Locking <= 2.8.1 – Unauthenticated SQL Injection

The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading…

Versions affectées

*-2.8.1

Correctif

2.8.2

Publication

08/11/2021

CVE-2021-24484 Élevée · 7,2
Secure Copy Content Protection and Content Locking

Secure Copy Content Protection and Content Locking <= 2.6.6 – SQL Injection

The get_reports() function in the Secure Copy Content Protection and Content Locking WordPress plugin before 2.6.7 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading…

Versions affectées

[*, 2.6.7)

Correctif

2.6.7

Publication

29/06/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités