WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Wp Content Copy Protector?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Wp Content Copy Protector — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: wp-content-copy-protector
  • 100000+ instalaciones activas

content copy protectioncontent-protectionimage protectionno right clickprevent copy

Estado de mantenimiento

  • Requiere PHP: 7.4+

Vulnerabilidades conocidas

11 CVEs conocidos registrados para Wp Content Copy Protector. Reportadas entre 2021 y 2024.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2024-49306 WP Content Copy Protection & No Right Click [wp-content-copy-protector] < 3.6.1 Falsificación de petición en sitios cruzados (CSRF) Media 4,3 < 3.6.1 3.6.1 2024-10-15
CVE-2023-36678 WP Content Copy Protection & No Right Click [wp-content-copy-protector] < 3.5.6 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,9 < 3.5.6 3.5.6 2023-07-04
CVE-2022-23983 WP Content Copy Protection & No Right Click [wp-content-copy-protector] < 3.4.5 Falsificación de petición en sitios cruzados (CSRF) Alta 8,8 < 3.4.5 3.4.5 2022-02-16
CVE-2021-24191 WP Content Copy Protection & No Right Click [wp-content-copy-protector] < 3.1.5 Autorización indebida Alta 8,8 < 3.1.5 3.1.5 2021-05-14
CVE-2021-24193 WP Content Copy Protection & No Right Click [wp-content-copy-protector] < 3.1.5 Autorización indebida Alta 8,8 < 3.1.5 3.1.5 2021-05-14
CVE-2021-24192 WP Content Copy Protection & No Right Click [wp-content-copy-protector] < 3.1.5 Autorización indebida Alta 8,8 < 3.1.5 3.1.5 2021-05-14
CVE-2021-24195 WP Content Copy Protection & No Right Click [wp-content-copy-protector] < 3.1.5 Autorización indebida Alta 8,8 < 3.1.5 3.1.5 2021-05-14
CVE-2021-24194 WP Content Copy Protection & No Right Click [wp-content-copy-protector] < 3.1.5 Autorización indebida Alta 8,8 < 3.1.5 3.1.5 2021-05-14

CVE-2024-49306

The WP Content Copy Protection & No Right Click plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.9. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2023-36678

Update the WordPress WP Content Copy Protection & No Right Click plugin to the latest available version (at least 3.5.6). LEE SE HYOUNG (hackintoanetwork) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WP Content Copy Protection & No Right Click Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.5.6.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2022-23983

Cross-Site Request Forgery (CSRF) vulnerability leading to plugin Settings Update discovered in WP Content Copy Protection & No Right Click WordPress plugin (versions <= 3.4.4).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2021-24191

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site Under Construction WordPress plugin before 1.8.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2021-24193

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics WordPress plugin before 2.12, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2021-24192

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2021-24195

Low privileged users could use the AJAX action "cp_plugins_do_button_job_later_callback" from multiple plugins of the WP-Buy vendor, to install any plugin (including a specific version) from the WordPress repository, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE. Note (WPScanTeam): The same AJAX action could also be used to activate installed plugins on the blog.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

CVE-2021-24194

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection - Limit Failed Login Attempts WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

+ 6 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2021-24189 WP Content Copy Protection & No Right Click [wp-content-copy-protector] < 3.1.5 Autorización indebida Alta 8,8 < 3.1.5 3.1.5 2021-05-14
CVE-2021-24190 WP Content Copy Protection & No Right Click [wp-content-copy-protector] < 3.1.5 Autorización indebida Alta 8,8 < 3.1.5 3.1.5 2021-05-14
CVE-2021-24188 WP Content Copy Protection & No Right Click [wp-content-copy-protector] < 3.1.5 Autorización indebida Alta 8,8 < 3.1.5 3.1.5 2021-04-22
WP Content Copy Protection & No Right Click [wp-content-copy-protector] < 3.1.5 Desconocido < 3.1.5 3.1.5 2021-04-22
WP Content Copy Protection & No Right Click [wp-content-copy-protector] < 3.4 Desconocido < 3.4 3.4 2021-04-22
WP Content Copy Protection & No Right Click [wp-content-copy-protector] < 3.4 Desconocido < 3.4 3.4

CVE-2021-24189

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptcha for admin login page WordPress plugin before 2.4, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2021-24190

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plugin before 1.5.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2021-24188

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Content Copy Protection & No Right Click WordPress plugin before 3.1.5, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

WP Content Copy Protection & No Right Click [wp-content-copy-protector] < 3.1.5

Arbitrary Plugin Installation and Activation vulnerability discovered by Bugbang in WordPress WP Content Copy Protection & No Right Click plugin (versions <= 3.1.4).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

WP Content Copy Protection & No Right Click [wp-content-copy-protector] < 3.4

The WP Content Copy Protection & No Right Click Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3. This is due to missing or incorrect nonce validation on the 'cp_plugins_do_button_job_later_callback' AJAX action. This makes it possible for unauthenticated attackers to install and activate other plugins via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WP Content Copy Protection & No Right Click [wp-content-copy-protector] < 3.4

The "cp_plugins_do_button_job_later_callback" AJAX action, from multiple plugins of the WP-Buy vendor, was lacking CSRF check, allowing attackers to make a logged in administrator install and active arbitrary plugins (including specific version) from the WordPress repository which could lead to more critical vulnerabilities like RCE.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.