Sploitus

CVE-2021-24931

7 known exploits for CVE-2021-24931

The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an SQL injection.

Ays-pro Secure Copy Content Protection And Content Locking
< 2.8.2
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
78.8% (100th percentile)
Weakness
CWE-89
NVD status
Modified
Published
2021-12-06
CVE-2021-24931 at NVD
Authoritative description, scoring and affected products

7 known exploits for CVE-2021-24931

Proof-of-concept code and exploit modules indexed by Sploitus