Impact
The vulnerability arises from improper neutralization of user‑supplied input during web page generation in the Secure Copy Content Protection and Content Locking plugin. This stored XSS flaw allows an attacker who can inject data into the plugin’s editable fields to have arbitrary JavaScript executed in the browsers of any visitor who views the affected content. The primary impact is that malicious code could be run client‑side, potentially leading to session hijacking, defacement, or phishing attacks. The weakness is classified as CWE‑79.
Affected Systems
Affected systems are WordPress installations using the Ays Pro Secure Copy Content Protection and Content Locking plugin with version numbers from the earliest release through 4.5.5 inclusive. No specific release is excluded in the advisory, so all versions up to and including 4.5.5 are vulnerable.
Risk and Exploitability
The CVSS base score is 5.9, indicating moderate severity. The EPSS score of less than 1 percent suggests that exploitation may be uncommon, and the vulnerability is not listed in the CISA KEV catalog. Practical exploitation would require an attacker to gain administrative or content‑creation access to the WordPress site and input malicious payloads into the plugin’s fields, which are then stored and delivered to all site visitors. The attack vector is therefore most plausibly remote via the web interface of the plugin, rather than through local privilege escalation.
OpenCVE Enrichment
EUVD