WP Content Copy Protection & No Right Click <= 3.5.9 - Cross-Site Request Forgery
medium
The WP Content Copy Protection & No Right Click plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.9. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forge...
- CVSS:
- 4.3
- Affected:
- up to 3.5.9
- Fixed in:
- 3.6.1
- Disclosed:
- Oct 15, 2024
CVE-2024-49306 on NVD →
WP Content Copy Protection & No Right Click <= 3.5.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The WP Content Copy Protection & No Right Click plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and...
- CVSS:
- 4.4
- Affected:
- up to 3.5.5
- Fixed in:
- 3.5.6
- Disclosed:
- Jul 4, 2023
CVE-2023-36678 on NVD →
WP Content Copy Protection & No Right Click <= 3.3 - Cross-Site Request Forgery to Arbitrary Plugin Installation/Activation
high
The WP Content Copy Protection & No Right Click Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3. This is due to missing or incorrect nonce validation on the 'cp_plugins_do_button_job_later_callback' AJAX action. This makes it possible for unauthenticated attackers...
- CVSS:
- 8.8
- Affected:
- up to 3.3
- Fixed in:
- 3.4
- Disclosed:
- Apr 22, 2021
WP Copy Protection & No Right Click <= 3.1.4 - Missing Authorization to Arbitrary Plugin Installation/Activation
high
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Content Copy Protection & No Right Click WordPress plugin before 3.1.5, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps at...
- CVSS:
- 8.8
- Affected:
- up to 3.1.5
- Fixed in:
- 3.1.5
- Disclosed:
- Apr 22, 2021
CVE-2021-24188 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database