ContentLock
ContentLock has 3 disclosed vulnerabilities in the WordSec catalog, all reported in 2024; all 3 are fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10. 2024 was the busiest year with 3 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 3 of the records (100%).
Every one of the 3 issues recorded for ContentLock has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, most of them (2) reported by Norbert Hofmann. The current release is tested up to WordPress 6.7.7.
CVE-2024-6024ContentLock <= 1.0.3 - Cross-Site Request Forgery to Group/Email Deletion
Read the full analysisVulnerability Records

ContentLock
Author
Adam Solymosi
EMAIL-BASED VERIFICATION ✔️ ContentLock is a simple solution for setting email-based access to your Pages, Posts, or Custom Post Types. Do you want to provide quick access to someone (or a whole group) via email only, without requiring any kind of registration? Here is your plugin! SECURE ACCESS TO YOUR CONTENT 🔑 ContentLock offers a solution that is independent of WordPress users and the registration system, allowing you to grant access to content that is hidden from other visitors. Compatible with popular page builders, editors and plugins: Gutenberg, Classic Editor, Elementor, Divi, etc. FEATURES 🚀 Create groups for standalone email lists Set access for multiple groups simultaneously Import emails from a CSV file Unlock content with an email verification code
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C