CVE-2024-33587 MEDIUM

CVE-2024-33587: WordPress Secure Copy Content Protection and Content Locking plugin <= 3.9.0 - Broken Access Control vulnerability

Vendor Copy Content Protection Team
Product Secure Copy Content Protection and Content Locking
Weakness CWE-862 · Missing authorization
Published April 29, 2024
Last update April 28, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Missing Authorization vulnerability in Copy Content Protection Team Secure Copy Content Protection and Content Locking.This issue affects Secure Copy Content Protection and Content Locking: from n/a through 3.9.0.

Explanation of Vulnerability in Simple Terms

02Summary

The Secure Copy Content Protection and Content Locking plugin through version 3.9.0 fails to properly check user permissions before allowing certain actions. An attacker without authentication can modify content or settings they should not have access to. This affects the integrity of protected content on sites using this plugin.

What an attacker can do

03Attacker Capabilities

Modify or alter protected content without having permission to do so.

Potential impact on your site

04Site Impact

Attackers can change protected content or plugin settings without logging in, compromising content integrity.

Conditions required to exploit

05Prerequisites

Network access to the site; no authentication or user interaction required.

Key dates

06Disclosure timeline

April 29, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE