CVE-2021-24188, CVE-2021-24189, CVE-2021-24190, CVE-2021-24191, CVE-2021-24192, CVE-2021-24193, CVE-2021-24194, CVE-2021-24195
The WP Content Copy Protection & No Right Click plugin before version 3.1.5 contains a vulnerability in its AJAX action 'cp_plugins_do_button_job_later_callback' that allows users with minimal privileges to install any plugin from the WordPress repository and activate arbitrary plugins on the site. This flaw could enable attackers to deploy vulnerable plugins or achieve remote code execution by installing malicious code through this mechanism.
Based on public CVE data (MITRE/NVD).