plugin

Wp Copyprotect Vulnerabilities

7 known security issues reported for the Wp Copyprotect WordPress plugin. Most recent disclosed Oct 4, 2023.

1 high 1 medium

Running Wp Copyprotect on your site? Check whether your installed version is affected.

Scan your site free

WP-CopyProtect [Protect your blog posts] [wp-copyprotect] <= 3.1.0 (unfixed + closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Chetan Gole WP-CopyProtect [Protect your blog posts] plugin <= 3.1.0 versions.

Affected:
up to 3.1.0
Fix:
No patched version reported
Disclosed:
Oct 4, 2023

CVE-2023-25025 on NVD →

WP-CopyProtect [Protect your blog posts] [wp-copyprotect] <= 3.1.0 (unfixed + closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Chetan Gole WP-CopyProtect [Protect your blog posts] plugin <= 3.1.0 versions.

Affected:
up to 3.1.0
Fix:
No patched version reported
Disclosed:
Oct 4, 2023

CVE-2023-37995 on NVD →

WP-CopyProtect [Protect your blog posts] <= 3.1.0 - Cross-Site Request Forgery via CopyProtect_options_page

medium

The WP-CopyProtect [Protect your blog posts] plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.0. This is due to missing or incorrect nonce validation on the CopyProtect_options_page function. This makes it possible for unauthenticated attackers to modify plugin sett...

CVSS:
4.3
Affected:
up to 3.1.0
Fix:
No patched version reported
Disclosed:
Jul 19, 2023

CVE-2023-25025 on NVD →

WP-CopyProtect [Protect your blog posts] [wp-copyprotect] < 3.1.0 (closed)

unknown

[en] A vulnerability classified as problematic was found in cchetanonline WP-CopyProtect up to 3.0.0. This vulnerability affects the function CopyProtect_options_page of the file wp-copyprotect.php. The manipulation of the argument CopyProtect_nrc_text leads to cross site scripting. The attack can be initiated remotely...

Affected:
up to 3.1.0
Fixed in:
3.1.0
Disclosed:
Jun 12, 2023

CVE-2015-10118 on NVD →

WP-CopyProtect [Protect your blog posts] <= 3.0.0 - Cross-Site Scripting

high

The WP-CopyProtect plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘CopyProtect_nrc_text’ parameter in versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
7.2
Affected:
up to 3.1.0
Fixed in:
3.1.0
Disclosed:
Jun 30, 2015

WP-CopyProtect [Protect your blog posts] [wp-copyprotect] < 3.1.0 (closed)

unknown

The WP-CopyProtect plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘CopyProtect_nrc_text’ parameter in versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

Affected:
up to 3.1.0
Fixed in:
3.1.0
Disclosed:
Jun 30, 2015

WP-CopyProtect [Protect your blog posts] [wp-copyprotect] < 3.1.0 (closed)

unknown

The WP-CopyProtect [Protect your blog posts] plugin for WordPress is vulnerable to a Persistent XSS attack on the settings screen, due to a lack of sanitation of user input, and lack of Cross-Site Request Forgery (CSRF) token (nonce).

Affected:
up to 3.1.0
Fixed in:
3.1.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database