CVE-2025-14442 MEDIUM

CVE-2025-14442: Secure Copy Content Protection and Content Locking <= 4.9.2 - Unauthenticated Sensitive Information Exposure via Exposed CSV Export File

Vendor Ays-Pro
Product Secure Copy Content Protection and Content Locking
Weakness CWE-552 · Files accessible externally
Published December 12, 2025
Last update April 8, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to sensitive information exposure due to storage of exported CSV files in a publicly accessible directory with predictable filenames in all versions up to, and including, 4.9.2. This makes it possible for unauthenticated attackers to access sensitive user data including emails, IP addresses, usernames, roles, and location data by directly accessing the exported CSV file.

Explanation of Vulnerability in Simple Terms

02Summary

Secure Copy Content Protection and Content Locking versions up to 4.9.2 expose sensitive information through improper file access controls. An attacker can read files that should be restricted without authentication. The vulnerability affects how the plugin manages access to protected content and files.

What an attacker can do

03Attacker Capabilities

Read files and content that should be restricted or protected by the plugin.

Potential impact on your site

04Site Impact

Sensitive content protected by the plugin may be exposed to unauthorized visitors.

Conditions required to exploit

05Prerequisites

Network access to the site; no authentication or user interaction required.

Key dates

06Disclosure timeline

December 12, 2025 CVE published
April 8, 2026 Record updated