CVE-2025-30905: WordPress Secure Copy Content Protection and Content Locking plugin <= 4.4.3 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Secure Copy Content Protection and Content Locking secure-copy-content-protection allows Stored XSS.This issue affects Secure Copy Content Protection and Content Locking: from n/a through <= 4.4.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30905?
CVE-2025-30905 is categorized as a stored Cross-site Scripting (XSS) vulnerability.
How do I fix CVE-2025-30905?
You can fix CVE-2025-30905 by updating Ays Pro Secure Copy Content Protection and Content Locking to version 4.4.4 or later.
What impact does CVE-2025-30905 have on my website?
CVE-2025-30905 can allow an attacker to inject malicious scripts into your site, potentially compromising user data.
Is my site affected by CVE-2025-30905?
If you are using versions of Ays Pro Secure Copy Content Protection and Content Locking up to 4.4.3, your site is affected by CVE-2025-30905.
What is stored XSS as reported in CVE-2025-30905?
Stored XSS in CVE-2025-30905 refers to a security flaw where malicious scripts are stored on the server and executed when users access the affected pages.