What the vulnerability does
01Description
The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to sensitive information exposure due to storage of exported CSV files in a publicly accessible directory with predictable filenames in all versions up to, and including, 4.9.2. This makes it possible for unauthenticated attackers to access sensitive user data including emails, IP addresses, usernames, roles, and location data by directly accessing the exported CSV file.
Explanation of Vulnerability in Simple Terms
02Summary
Secure Copy Content Protection and Content Locking versions up to 4.9.2 expose sensitive information through improper file access controls. An attacker can read files that should be restricted without authentication. The vulnerability affects how the plugin manages access to protected content and files.
What an attacker can do
03Attacker Capabilities
Read files and content that should be restricted or protected by the plugin.
Potential impact on your site
04Site Impact
Sensitive content protected by the plugin may be exposed to unauthorized visitors.
Conditions required to exploit
05Prerequisites
Network access to the site; no authentication or user interaction required.
Key dates
06Disclosure timeline
December 12, 2025
CVE published
April 8, 2026
Record updated