QID 731089

Date Published: 2024-02-06

QID 731089: WordPress Secure Copy Content Protection and Content Locking SQL Injection Vulnerability

WordPress Copy Protection plugin is aimed at protecting web content from being plagiarized.

Vulnerable versions of Secure Copy Content Protection and Content Locking WordPress plugin fail to escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an SQL injection.

Affected Versions:
Secure Copy Content Protection and Content Locking WordPress plugin prior to 2.8.2

QID Detection Logic:
This unauthenticated QID launches a SQL statement to the wp-admin/admin-ajax.php?action=ays_sccp_results_export_file URI.

Successful exploitation allows an unauthenticated, remote attacker to conduct SQL injection attacks against a targeted system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade to Secure Copy Content Protection and Content Locking WordPress plugin 2.8.2 or later versions to remediate this vulnerability.

    Vendor References

    CVEs related to QID 731089

    Software Advisories
    Advisory ID Software Component Link
    Secure Copy Content Protection and Content Locking WordPress 2.8.2 and later URL Logo wordpress.org/plugins/secure-copy-content-protection/#description