CVE-2021-24931

Secure Copy Content Protection and Content Locking < 2.8.2 - Unauthenticated SQL Injection

Basic Information

CVE State
PUBLISHED
Reserved Date
January 14, 2021
Published Date
December 06, 2021
Last Updated
August 03, 2024
Vendor
Unknown
Product
Secure Copy Content Protection and Content Locking
Description
The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an SQL injection.
Tags
wordpress nuclei_scanner

CVSS Scores

CVSS v3.1

9.8 - CRITICAL

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0

7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Score

Score
67.22% (Percentile: 98.43%) as of 2025-06-06

Exploit Status

Exploited in the Wild
Yes (2025-05-09 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
The Shadowserver (via CIRCL) 2025-05-09 00:00:00 UTC

Scanner Integrations

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Detected by Nuclei

  • Added to KEVIntel