Vulnerability record · CVE-2021-24931 · published 6 December 2021
CVE-2021-24931: WordPress Secure Copy Content Protection plugin unauthenticated SQL injection
Ays Pro · Secure Copy Content Protection And Content Locking
The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 fails to escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action before using it in a SQL statement. Because that action is reachable by unauthenticated users, any remote attacker can inject SQL into the site's database. This is a critical flaw in a widely deployed plugin class, and exploitation is publicly documented.
Description
The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an SQL injection.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable SQL injection with CVSS 9.8, public exploit references and very high EPSS, giving attackers full database access.
What it is
The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 fails to escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action before using it in a SQL statement. Because that action is reachable by unauthenticated users, any remote attacker can inject SQL into the site's database. This is a critical flaw in a widely deployed plugin class, and exploitation is publicly documented.
Impact
An attacker can read, modify or delete arbitrary data in the WordPress database, including user credentials and hashes, and can potentially pivot to further compromise of the host. Full loss of confidentiality, integrity and availability of the database is possible.
Attack surface
Reached over the network via the WordPress AJAX endpoint handling the ays_sccp_results_export_file action, with the sccp_id parameter as the injection point. No authentication or user interaction is required, as confirmed by the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.788 probability, 99.57th percentile) and multiple references are tagged Exploit, including Packet Storm and WPScan entries, indicating public exploit code exists.
What to do
- Update the Secure Copy Content Protection and Content Locking plugin to version 2.8.2 or later immediately.
- If patching cannot be done at once, deactivate or remove the plugin until it can be updated.
- Apply a WAF rule blocking or sanitizing the sccp_id parameter on the ays_sccp_results_export_file AJAX action.
- Audit the WordPress database and user accounts for signs of tampering or unauthorized administrative users.
- Rotate WordPress salts and any credentials stored in the database if compromise is suspected.
Detection
- Search web server and WAF logs for requests to admin-ajax.php with action=ays_sccp_results_export_file and suspicious sccp_id values containing SQL syntax.
- Monitor for SQL error responses or unusual query patterns originating from the WordPress application.
- Review database and file integrity for unexpected changes, new admin users or modified plugin files.
- Check for outbound connections or dropped webshells following exploitation attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/165946/WordPress-Secure-Copy-Content-Protection-And-Content-Locking-2.8.1-SQL-Injec | ExploitThird Party AdvisoryVDB Entry |
| https://wpscan.com/vulnerability/1cd52d61-af75-43ed-9b99-b46c471c4231 | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/165946/WordPress-Secure-Copy-Content-Protection-And-Content-Locking-2.8.1-SQL-Injec | ExploitThird Party AdvisoryVDB Entry |
| https://wpscan.com/vulnerability/1cd52d61-af75-43ed-9b99-b46c471c4231 | ExploitThird Party Advisory |
Track CVE-2021-24931 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-24931), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.