CVE-2024-6888: Secure Copy Content Protection and Content Locking < 4.1.7 - Admin+ Stored XSS
The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6888?
CVE-2024-6888 has a medium severity rating, as it allows high privilege users to perform Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-6888?
To fix CVE-2024-6888, update the Secure Copy Content Protection and Content Locking plugin to version 4.1.7 or later.
Who is affected by CVE-2024-6888?
CVE-2024-6888 affects installations of the Secure Copy Content Protection and Content Locking WordPress plugin prior to version 4.1.7.
What type of vulnerability is CVE-2024-6888?
CVE-2024-6888 is categorized as a Stored Cross-Site Scripting (XSS) vulnerability.
Can unprivileged users exploit CVE-2024-6888?
No, unprivileged users cannot exploit CVE-2024-6888 as it requires high privilege access to perform the attack.