QID 731089
Date Published: 2024-02-06
QID 731089: WordPress Secure Copy Content Protection and Content Locking SQL Injection Vulnerability
WordPress Copy Protection plugin is aimed at protecting web content from being plagiarized.
Vulnerable versions of Secure Copy Content Protection and Content Locking WordPress plugin fail to escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an SQL injection.
Affected Versions:
Secure Copy Content Protection and Content Locking WordPress plugin prior to 2.8.2
QID Detection Logic:
This unauthenticated QID launches a SQL statement to the wp-admin/admin-ajax.php?action=ays_sccp_results_export_file URI.
Successful exploitation allows an unauthenticated, remote attacker to conduct SQL injection attacks against a targeted system.
- Secure Copy Content Protection and Content Locking -
wordpress.org/plugins/secure-copy-content-protection/#developers
CVEs related to QID 731089
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Secure Copy Content Protection and Content Locking WordPress 2.8.2 and later |
|