Stored Cross-Site Scripting in Secure Copy Content Protection for WordPress
CVE-2026-2367
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 February 2026
What is CVE-2026-2367?
The Secure Copy Content Protection plugin for WordPress is susceptible to a Stored Cross-Site Scripting flaw through the 'ays_block' shortcode. This vulnerability arises from inadequate input sanitization and output escaping of user-supplied attributes. Authenticated users with contributor-level permissions can exploit this issue to inject malicious scripts into web pages, leading to potential unauthorized access or data manipulation whenever a user views the compromised page. It affects all versions up to and including 5.0.1, posing significant risks to website security if not addressed.
Affected Version(s)
Secure Copy Content Protection and Content Locking 0 <= 5.0.1