CVE-2021-24931
The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an SQL injection.
- Affected products
- Secure Copy Content Protection/Content Locking
- Ays-pro Secure Copy Content Protection And Content Locking
- < 2.8.2
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 78.8% (100th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2021-12-06
CVE-2021-24931 at NVD
7 known exploits for CVE-2021-24931
Proof-of-concept code and exploit modules indexed by Sploitus
Exploits
Wordpress Secure Copy Content Protection And Content Locking Sccp_id Unauthenticated SQL Injection
WordPress Secure Copy Content Protection And Content Locking 2.8.1 SQL Injection
WordPress Secure Copy Content Protection and Content Locking 2.8.1 Plugin - SQL-Injection Exploit
WordPress Plugin Secure Copy Content Protection and Content Locking 2.8.1 - SQL-Injection (Unauthenticated)
Wordpress Secure Copy Content Protection and Content Locking sccp_id Unauthenticated SQLi
Secure Copy Content Protection and Content Locking < 2.8.2 - Unauthenticated SQL Injection