First published: Tue Apr 01 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Secure Copy Content Protection and Content Locking allows Stored XSS. This issue affects Secure Copy Content Protection and Content Locking: from n/a through 4.4.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ays Pro Secure Copy Content Protection | <=4.4.3 | |
WordPress Secure Copy Content Protection | <=4.4.3 |
Update the WordPress Secure Copy Content Protection and Content Locking plugin to the latest available version (at least 4.4.5).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30905 is categorized as a stored Cross-site Scripting (XSS) vulnerability.
You can fix CVE-2025-30905 by updating Ays Pro Secure Copy Content Protection and Content Locking to version 4.4.4 or later.
CVE-2025-30905 can allow an attacker to inject malicious scripts into your site, potentially compromising user data.
If you are using versions of Ays Pro Secure Copy Content Protection and Content Locking up to 4.4.3, your site is affected by CVE-2025-30905.
Stored XSS in CVE-2025-30905 refers to a security flaw where malicious scripts are stored on the server and executed when users access the affected pages.