PT-2026-48832 · WordPress · Secure Copy Content Protection/Content Locking

·

CVE-2026-9269

·

Published

2026-06-12

·

Updated

2026-06-12

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Secure Copy Content Protection and Content Locking versions prior to 5.1.5
Description The plugin fails to sanitize and escape certain settings, enabling high-privilege users, such as administrators, to execute Stored Cross-Site Scripting attacks. This occurs even in environments where the unfiltered html capability is disabled, such as multisite setups. The issue is specifically linked to the ays sccp sub icon image parameter.
Recommendations Update to version 5.1.5 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-9269

Affected Products

Secure Copy Content Protection/Content Locking