CopySafe Web Protection <= 5.1 - Missing Authorization
medium
The CopySafe Web Protection plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 5.1
- Fixed in:
- 5.3
- Disclosed:
- Sep 26, 2025
CVE-2025-60127 on NVD →
CopySafe Web Protection [wp-copysafe-web] < 3.15
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ArtistScope CopySafe Web Protection allows Stored XSS.This issue affects CopySafe Web Protection: from n/a through 3.14.
- Affected:
- up to 3.15
- Fixed in:
- 3.15
- Disclosed:
- Jul 21, 2024
CVE-2024-37514 on NVD →
CopySafe Web Protection [wp-copysafe-web] < 4.0
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ArtistScope CopySafe Web Protection allows Reflected XSS.This issue affects CopySafe Web Protection: from n/a through 3.15.
- Affected:
- up to 4.0
- Fixed in:
- 4.0
- Disclosed:
- Jul 21, 2024
CVE-2024-38781 on NVD →
CopySafe Web Protection <= 3.15 - Reflected Cross-Site Scripting
medium
The CopySafe Web Protection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...
- CVSS:
- 6.1
- Affected:
- up to 3.15
- Fixed in:
- 4.0
- Disclosed:
- Jul 19, 2024
CVE-2024-38781 on NVD →
CopySafe Web Protection <= 3.14 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The CopySafe Web Protection plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in...
- CVSS:
- 6.4
- Affected:
- up to 3.14
- Fixed in:
- 3.15
- Disclosed:
- Jul 5, 2024
CVE-2024-37514 on NVD →
CopySafe Web Protection [wp-copysafe-web] < 3.14
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ArtistScope CopySafe Web Protection plugin <= 3.13 versions.
- Affected:
- up to 3.14
- Fixed in:
- 3.14
- Disclosed:
- May 26, 2023
CVE-2023-29098 on NVD →
CopySafe Web Protection <= 3.13 - Unauthenticated Stored Cross-Site Scripting
high
The CopySafe Web Protection plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in versions up to, and including, 3.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execu...
- CVSS:
- 7.2
- Affected:
- up to 3.13
- Fixed in:
- 3.14
- Disclosed:
- Apr 3, 2023
CVE-2023-29098 on NVD →
CopySafe Web Protection [wp-copysafe-web] < 2.6
unknown
[en] There is CSRF in the CopySafe Web Protection plugin before 2.6 for WordPress, allowing attackers to change plugin settings.
- Affected:
- up to 2.6
- Fixed in:
- 2.6
- Disclosed:
- Apr 24, 2017
CVE-2017-8100 on NVD →
CopySafe Web Protection < 2.6 - Cross-Site Request Forgery
medium
There is CSRF in the CopySafe Web Protection plugin before 2.6 for WordPress, allowing attackers to change plugin settings.
- CVSS:
- 6.5
- Affected:
- up to 2.6
- Fixed in:
- 2.6
- Disclosed:
- Apr 7, 2017
CVE-2017-8100 on NVD →
CopySafe Web Protection [wp-copysafe-web] < 2.6
unknown
Cross-Site Request Forgery (CSRF) vulnerability in WordPress CopySafe Web Protect plugin allows an attacker to change the plugin settings.
Update WordPress CopySafe Web Protect plugin to the latest available version (at least version 2.6).
- Affected:
- up to 2.6
- Fixed in:
- 2.6
- Disclosed:
- Apr 7, 2017
CopySafe Web Protection [wp-copysafe-web] <= 4.3 (unfixed)
unknown
- Affected:
- up to 4.3
- Fix:
- No patched version reported
CVE-2025-60127 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database