Ays-pro
Ays-pro Secure Copy Content Protection AND Content Locking: vulnerabilidades y CVE
Ays-pro Secure Copy Content Protection AND Content Locking tiene 16 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses6
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-9269 | Baja (3.5) | 0.24% | — | 12 jun 2026 | The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site… |
| CVE-2026-2367 | Media (6.4) | 0.20% | — | 25 feb 2026 | The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ays_block' shortcode in all versions up to, and including, 5.0.1 due to… |
| CVE-2026-25335 | Media (4.3) | 0.28% | — | 19 feb 2026 | Missing Authorization vulnerability in Ays Pro Secure Copy Content Protection and Content Locking secure-copy-content-protection allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects… |
| CVE-2026-1320 | Alta (7.2) | 0.27% | — | 12 feb 2026 | The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' HTTP header in all versions up to, and including, 4.9.8 due to… |
| CVE-2025-14442 | Media (5.3) | 0.32% | — | 12 dic 2025 | The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to sensitive information exposure due to storage of exported CSV files in a publicly accessible directory with predictable… |
| CVE-2025-14159 | Media (4.3) | 0.16% | — | 12 dic 2025 | The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.9.2. This is due to missing nonce validation on the… |
| CVE-2025-32133 | Media (5.9) | 0.41% | — | 4 abr 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Secure Copy Content Protection and Content Locking secure-copy-content-protection allows Stored XSS.This… |
| CVE-2025-30905 | Alta (7.1) | 0.39% | — | 1 abr 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Secure Copy Content Protection and Content Locking secure-copy-content-protection allows Stored XSS.This… |
| CVE-2024-47306 | Alta (7.1) | 0.32% | — | 6 oct 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Secure Copy Content Protection and Content Locking secure-copy-content-protection-subscribe-to-view allows… |
| CVE-2024-6889 | Media (4.8) | 0.37% | — | 4 sept 2024 | The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site… |
| CVE-2024-6888 | Media (4.8) | 0.40% | — | 4 sept 2024 | The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site… |
| CVE-2024-6138 | Media (4.8) | 0.37% | — | 11 jul 2024 | The Secure Copy Content Protection and Content Locking WordPress plugin before 4.0.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site… |
| CVE-2024-32787 | Media (4.3) | 0.28% | — | 9 jun 2024 | Missing Authorization vulnerability in Copy Content Protection Team Secure Copy Content Protection and Content Locking.This issue affects Secure Copy Content Protection and Content Locking: from n/a through 3.7.1. |
| CVE-2024-33587 | Media (5.3) | 0.38% | — | 29 abr 2024 | Missing Authorization vulnerability in Copy Content Protection Team Secure Copy Content Protection and Content Locking.This issue affects Secure Copy Content Protection and Content Locking: from n/a through 3.9.0. |
| CVE-2021-24931 | Crítica (9.8) | 79% | — | 6 dic 2021 | The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and… |
| CVE-2021-24484 | Alta (7.2) | 1.3% | — | 2 ago 2021 | The get_reports() function in the Secure Copy Content Protection and Content Locking WordPress plugin before 2.6.7 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.