CVE · High

CVE-2021-24190 — WP Content Copy Protection & No Right Click [wp-content-copy-protector] < 3.1.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24188, CVE-2021-24189, CVE-2021-24190, CVE-2021-24191, CVE-2021-24192, CVE-2021-24193, CVE-2021-24194, CVE-2021-24195 WP Content Copy Protection & No Right Click [wp-content-copy-protector] < 3.1.5 Improper Authorization High 8.8 < 3.1.5 3.1.5 2021-04-22

CVE-2021-24188, CVE-2021-24189, CVE-2021-24190, CVE-2021-24191, CVE-2021-24192, CVE-2021-24193, CVE-2021-24194, CVE-2021-24195

The WP Content Copy Protection & No Right Click plugin before version 3.1.5 contains a vulnerability in its AJAX action 'cp_plugins_do_button_job_later_callback' that allows users with low-level privileges to install arbitrary plugins from the WordPress repository or activate any plugin already present on the site. This flaw enables attackers to deploy vulnerable plugins that could potentially lead to remote code execution or other severe security compromises.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.