← Vulnerability feed

Vulnerability record · CVE-2021-24931 · published 6 December 2021

CVE-2021-24931: WordPress Secure Copy Content Protection plugin unauthenticated SQL injection

Ays Pro · Secure Copy Content Protection And Content Locking

The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 fails to escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action before using it in a SQL statement. Because that action is reachable by unauthenticated users, any remote attacker can inject SQL into the site's database. This is a critical flaw in a widely deployed plugin class, and exploitation is publicly documented.

9.8 CVSS 3.1 Critical EPSS 79% · top 0.4% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an SQL injection.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable SQL injection with CVSS 9.8, public exploit references and very high EPSS, giving attackers full database access.

What it is

The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 fails to escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action before using it in a SQL statement. Because that action is reachable by unauthenticated users, any remote attacker can inject SQL into the site's database. This is a critical flaw in a widely deployed plugin class, and exploitation is publicly documented.

Impact

An attacker can read, modify or delete arbitrary data in the WordPress database, including user credentials and hashes, and can potentially pivot to further compromise of the host. Full loss of confidentiality, integrity and availability of the database is possible.

Attack surface

Reached over the network via the WordPress AJAX endpoint handling the ays_sccp_results_export_file action, with the sccp_id parameter as the injection point. No authentication or user interaction is required, as confirmed by the CVSS vector AV:N/AC:L/PR:N/UI:N.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.788 probability, 99.57th percentile) and multiple references are tagged Exploit, including Packet Storm and WPScan entries, indicating public exploit code exists.

What to do

  • Update the Secure Copy Content Protection and Content Locking plugin to version 2.8.2 or later immediately.
  • If patching cannot be done at once, deactivate or remove the plugin until it can be updated.
  • Apply a WAF rule blocking or sanitizing the sccp_id parameter on the ays_sccp_results_export_file AJAX action.
  • Audit the WordPress database and user accounts for signs of tampering or unauthorized administrative users.
  • Rotate WordPress salts and any credentials stored in the database if compromise is suspected.

Detection

  • Search web server and WAF logs for requests to admin-ajax.php with action=ays_sccp_results_export_file and suspicious sccp_id values containing SQL syntax.
  • Monitor for SQL error responses or unusual query patterns originating from the WordPress application.
  • Review database and file integrity for unexpected changes, new admin users or modified plugin files.
  • Check for outbound connections or dropped webshells following exploitation attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-24931 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2021-24484Ays-pro secure copy content protection and content locking sql injection vulnerabilityThe get_reports() function in the Secure Copy Content Protection and Content Locking WordPress plugin before 2.6.7 did not use whitelist or validate …EPSS 1.3%4.8CVE-2024-6888Ays-pro secure copy content protection and content locking cross-site scripting vulnerabilityThe Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could a…EPSS 0.40%4.8CVE-2024-6889Ays-pro secure copy content protection and content locking cross-site scripting vulnerabilityThe Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could a…EPSS 0.37%4.8CVE-2024-6138Ays-pro secure copy content protection and content locking cross-site scripting vulnerabilityThe Secure Copy Content Protection and Content Locking WordPress plugin before 4.0.9 does not sanitise and escape some of its settings, which could a…EPSS 0.37%9.8CVE-2026-76461Cisco AsyncOS email parsing SQL injection allows root command executionCisco AsyncOS Software for Cisco Secure Email Gateway fails to properly validate email parsing input, allowing crafted email messages containing mali…KEVEPSS 28%analysed9.3CVE-2026-9586Sangoma Switchvox unauthenticated SQL injection in /pa endpointSangoma Switchvox SMB Edition 8.3 (104997) fails to sanitize the PhoneIP value from XML content beginning with <PolycomIPPhone> before concatenating …KEVEPSS 19%analysed10.0CVE-2026-72898Metabase unauthenticated SQL injection in reset_password endpointMetabase exposes a database endpoint, '/reset_password', that fails to neutralize attacker-supplied SQL, allowing arbitrary SQL injection. Because th…KEVEPSS 19%analysed5.9CVE-2026-60137WordPress WP_Query author__not_in SQL injectionWordPress core fails to properly sanitise the author__not_in parameter of WP_Query in versions before 6.8.6, 6.9.5 and 7.0.2, allowing SQL injection …KEVEPSS 5.9%analysed

Source: NIST National Vulnerability Database (record CVE-2021-24931), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.