Vulnerabilities / WPComplete / WPSEC-2026-0609

WPComplete <= 2.9.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Course Name

Medium 6.4 CWE-79Fixed in 2.9.5.8
ID
WPSEC-2026-0609
Plugin
WPComplete (wpcomplete)
Affected
from 2.3 before 2.9.5.8
Remediation
Update to 2.9.5.8 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Weakness
CWE-79
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-07
Attack surface
WPComplete on WPSec AttackSurface
Fix released
Published

Description

The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via course names in versions 2.3 up to, and including, 2.9.5.7. The cause is insufficient input sanitization and output escaping: a course name submitted through the post metabox or the posts-list 'Assign to' bulk action is decoded again whenever it is read back and printed without escaping in the quick-edit course dropdown, the posts-list course column, the bulk-action inline script, the dashboard widget and the course and user completion reports. This makes it possible for authenticated attackers with contributor-level access and above to inject arbitrary web scripts that execute when an administrator views the affected admin pages.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0