S4E just found a critical-severity finding from cve-2022-27924 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Oct 27, 2025

CVE-2024-6690 Scanner

CVE-2024-6690 Scanner - Open Redirect vulnerability in WP Content Copy Protection & No Right Click

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-6690
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirection of users to external sites

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
wccp-pro
AFFECTED< 15.3SAFE ✓≥ 15.3
Updated Sep 10, 2026View on NVD →
Detail

WP Content Copy Protection & No Right Click is used on WordPress sites to prevent content theft and disable right-click functionalities, primarily employed by website owners seeking to protect intellectual property. The plugin is typically adopted by e-commerce, educational, and other content-driven sites to mitigate unauthorized copying. Website administrators prefer this plugin for its ability to prevent casual users from easily copying text and images from their web pages. The plugin works by disabling standard browser functionality like right-click and context menus, often accompanied by alert messages to discourage copying. It is compatible with various WordPress themes and integrates seamlessly within the site's existing design. Additionally, its versatility and ease of use contribute to its popularity among novice and experienced WordPress users alike.

Open Redirect vulnerabilities occur when an attacker is able to manipulate a URL on a trusted website, resulting in redirection of traffic to a different, potentially malicious site. This type of vulnerability can be leveraged in phishing attacks, tricking users into entering sensitive information on impostor websites that appear legitimate. In the context of the WP Content Copy Protection & No Right Click plugin, the flaw exists in the handling of URLs through the referrer parameter. This flaw can allow attackers to exploit web traffic, redirecting unsuspecting users without their knowledge or consent. As a medium severity vulnerability, it emphasizes the importance of maintaining updated and secure software components. Such vulnerabilities underline potential risks in web browsing that users need to be cautious of.

The vulnerability lies within the "no-js.php" file of the WP Content Copy Protection & No Right Click plugin, specifically in the referrer URL parameter. This endpoint inadvertently processes and allows external redirection requests, which makes it susceptible to exploitation. Attackers can construct malicious URLs that take advantage of this parameter, effectively altering user navigation to deceitful sites. The vulnerability leverages an improper validation or lack of strict URL filtering, which fails to discern potentially malicious redirection targets. Consequently, the improper handling results in the browser's redirection to unintended locations, making user security potentially compromised. Documented in related CVEs, it exposes the fact that small configuration oversights in plugins can lead to significant security ramifications.

Exploitation of this vulnerability could have various implications, most notably facilitating phishing attacks and the spread of malware. By redirecting users to malicious sites, attackers can solicit sensitive information under the guise of legitimacy, such as login credentials or financial details. Furthermore, unsuspecting users might unknowingly download malicious software, leading to device compromise and data theft. The high frequency of web plugin usage amplifies the scope of possible effects, potentially impacting thousands of users globally. Continued exploitation can undermine user trust in legitimate brands and platforms, resulting in broader security concerns. Mitigating such risks reinforces the importance of continuous vigilance and timely patch management by website administrators.

REFERENCES

Solution Advice
  • Update the WP Content Copy Protection & No Right Click plugin to version 15.3 or later to mitigate the vulnerability.
  • Regularly audit and monitor installed plugins for available patches and updates.
  • Create backup solutions and recovery plans for configurations to prevent data loss during security upgrades.
  • Enable security-focused plugins or applications capable of flagging or blocking unauthorized redirection attempts.
  • Conduct regular penetration testing to identify and correct similar vulnerabilities in web applications.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-6690 Scanner - Open Redirect vulnerability in WP Content Copy Protection & No Right Click | S4E