Executive brief
WPComplete is a WordPress plugin used by site owners to track student progress in online courses. A security flaw allows an attacker to inject malicious scripts into the website's pages. If an administrator or another user views the affected page, the script could steal their session information or perform unauthorized actions on their behalf.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the Nexcess WPComplete plugin for WordPress due to improper neutralization of input during web page generation. The flaw allows an authenticated attacker with low-level privileges to inject malicious scripts into the database, which are then executed in the browser of any user who visits the affected page. This typically occurs because the plugin fails to properly sanitize or escape user-supplied data before rendering it in the administrative interface or on the front end. The vulnerability affects versions up to 2.9.5.4. Users are advised to check for updates from the vendor.
Affected products
- Nexcess WPComplete <= 2.9.5.4
Timeline
- 2026-05-27: advisory: Initial disclosure of CVE-2026-42750