WPComplete <= 2.9.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Course Name
- ID
- WPSEC-2026-0609
- Plugin
- WPComplete (wpcomplete)
- Affected
- from 2.3 before 2.9.5.8
- Remediation
- Update to 2.9.5.8 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Weakness
- CWE-79
- Usage
- Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-07
- Attack surface
- WPComplete on WPSec AttackSurface
- Fix released
- Published
Description
The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via course names in versions 2.3 up to, and including, 2.9.5.7. The cause is insufficient input sanitization and output escaping: a course name submitted through the post metabox or the posts-list 'Assign to' bulk action is decoded again whenever it is read back and printed without escaping in the quick-edit course dropdown, the posts-list course column, the bulk-action inline script, the dashboard widget and the course and user completion reports. This makes it possible for authenticated attackers with contributor-level access and above to inject arbitrary web scripts that execute when an administrator views the affected admin pages.
References
- https://wpsec.com/vuln/WPSEC-2026-0609/
- https://plugins.svn.wordpress.org/wpcomplete/tags/2.9.5.8/
- https://wordpress.org/plugins/wpcomplete/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS