CVE-2025-14442

MEDIUM

WordPress <4.9.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to sensitive information exposure due to storage of exported CSV files in a publicly accessible directory with predictable filenames in all versions up to, and including, 4.9.2. This makes it possible for unauthenticated attackers to access sensitive user data including emails, IP addresses, usernames, roles, and location data by directly accessing the exported CSV file.

Scores

CVSS v3 5.3
EPSS 0.0007
EPSS Percentile 20.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-552
Status published
Products (1)
ays-pro/Secure Copy Content Protection and Content Locking < 4.9.2
Published Dec 12, 2025
Tracked Since Feb 18, 2026