Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Secure Copy Content Protection and Content Locking allows Stored XSS. This issue affects Secure Copy Content Protection and Content Locking: from n/a through 4.4.3.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-9475 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Secure Copy Content Protection and Content Locking allows Stored XSS. This issue affects Secure Copy Content Protection and Content Locking: from n/a through 4.4.3. |
Fixes
Solution
Update the WordPress Secure Copy Content Protection and Content Locking plugin to the latest available version (at least 4.4.5).
Workaround
No workaround given by the vendor.
References
History
Tue, 01 Apr 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Secure Copy Content Protection and Content Locking allows Stored XSS. This issue affects Secure Copy Content Protection and Content Locking: from n/a through 4.4.3. | |
| Title | WordPress Secure Copy Content Protection and Content Locking plugin <= 4.4.3 - Cross Site Scripting (XSS) vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2025-04-02T13:23:49.492Z
Reserved: 2025-03-26T09:21:38.618Z
Link: CVE-2025-30905
No data.
Status : Awaiting Analysis
Published: 2025-04-01T21:15:45.863
Modified: 2025-04-02T14:58:07.527
Link: CVE-2025-30905
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:26:04Z
EUVD