PT-2021-15734 · WordPress · Wp Content Copy Protection & No Right Click

Bugbang

·

Published

2021-05-14

·

Updated

2022-08-30

·

CVE-2021-24188

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: WP Content Copy Protection & No Right Click WordPress plugin versions prior to 3.1.5
Description: The issue allows low-privileged users to exploit the AJAX action 'cp plugins do button job later callback' to install any plugin, including specific versions, from the WordPress repository and activate arbitrary plugins from the blog. This could enable attackers to install vulnerable plugins, potentially leading to more critical issues.
Recommendations: For WP Content Copy Protection & No Right Click WordPress plugin versions prior to 3.1.5, update to version 3.1.5 or later to resolve the issue.

Exploit

Fix

RCE

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-24188

Affected Products

Wp Content Copy Protection & No Right Click