First published: Mon Dec 06 2021(Updated: )
The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an SQL injection.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ays-pro Secure Copy Content Protection And Content Locking | <2.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24931 is a vulnerability in the Secure Copy Content Protection and Content Locking WordPress plugin before version 2.8.2 that allows SQL injection.
CVE-2021-24931 affects the Secure Copy Content Protection and Content Locking plugin by not properly escaping the sccp_id parameter in the ays_sccp_results_export_file AJAX action, allowing SQL injection.
Yes, CVE-2021-24931 is classified as a critical vulnerability with a severity value of 9.8.
To fix the CVE-2021-24931 vulnerability, update the Secure Copy Content Protection and Content Locking plugin to version 2.8.2 or later.
You can find more information about CVE-2021-24931 at the following references: [Link 1](http://packetstormsecurity.com/files/165946/WordPress-Secure-Copy-Content-Protection-And-Content-Locking-2.8.1-SQL-Injection.html), [Link 2](https://wpscan.com/vulnerability/1cd52d61-af75-43ed-9b99-b46c471c4231).