Executive brief
The Secure Copy Content Protection and Content Locking plugin for WordPress, which is used to prevent unauthorized copying of website content, contains a security flaw. This vulnerability allows high-privileged users, such as site administrators, to inject malicious scripts into the website's settings. This is particularly significant in multi-site environments where even administrators are normally restricted from adding custom scripts to prevent them from compromising the entire network or other users' sessions.
Technical details
The Secure Copy Content Protection and Content Locking plugin for WordPress fails to properly sanitize and escape the 'ays_sccp_sub_icon_image' parameter within its settings page. This oversight results in a Stored Cross-Site Scripting (XSS) vulnerability. An authenticated attacker with high privileges (such as an administrator) can inject malicious JavaScript into the plugin settings. This script will then execute in the browser of any user who visits the affected settings page. This bypasses 'unfiltered_html' restrictions typically enforced in WordPress Multisite configurations. The issue is fixed in version 5.1.5.
Affected products
- ays-pro Secure Copy Content Protection and Content Locking < 5.1.5
Timeline
- 2026-05-22: disclosed: Publicly published by WPScan
- 2026-06-12: advisory: NVD publication date
- 2026-05-22: patched: Fixed version 5.1.5 released