CVE-2026-9269: Secure Copy Content Protection and Content Locking < 5.1.5 - Admin+ Stored XSS via ays_sccp_sub_icon_image Parameter
The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Secure Copy Content Protection and Content Locking WordPress pluginto a version that resolves this vulnerability.Fixed in 5.1.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9269?
The severity of CVE-2026-9269 is classified as low with a CVSS score of 3.5.
How do I fix CVE-2026-9269?
To fix CVE-2026-9269, upgrade the Secure Copy Content Protection and Content Locking plugin to version 5.1.5 or later.
What type of vulnerability is CVE-2026-9269?
CVE-2026-9269 is a Stored Cross-Site Scripting (XSS) vulnerability.
Who is affected by CVE-2026-9269?
CVE-2026-9269 affects high privilege users, such as admins, using versions of the plugin prior to 5.1.5.
What could an attacker achieve with CVE-2026-9269?
An attacker could exploit CVE-2026-9269 to perform Stored Cross-Site Scripting attacks on a vulnerable WordPress site.