CVE-2025-1404
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Mar 1, 2025
CWE ID 862
Summary
CVE-2025-1404 is a vulnerability affecting the Secure Copy Content Protection and Content Locking plugin for WordPress. The issue lies in the ays_sccp_reports_user_search() function, which lacks sufficient capability checks. Consequently, unauthenticated attackers can exploit this flaw to retrieve a list of registered user emails, posing a significant risk to websites using the affected plugin versions up to 4.4.7.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.