Executive brief
WPComplete is a WordPress plugin used to track student progress in online courses and membership sites. A security flaw allows logged-in users with low-level 'Subscriber' permissions to perform actions they should not be authorized to do. This could allow students or members to manipulate course completion data or other plugin settings, potentially disrupting site operations or bypassing course requirements.
Technical details
The WPComplete plugin for WordPress (versions <= 2.9.5.5) contains a broken access control vulnerability due to missing authorization checks (CWE-862). An authenticated attacker with Subscriber-level privileges can exploit this flaw over the network without user interaction. The vulnerability allows these low-privileged users to execute functions or modify data that should be restricted to higher-privileged roles. The issue is addressed in version 2.9.5.6.
Affected products
- Nexcess / StellarWP WPComplete <= 2.9.5.5
Timeline
- 2026-05-31: disclosed: Reported by Md. Minaruzzaman Shovon
- 2026-06-26: advisory: Published by Patchstack and NVD
- 2026-06-26: patched: Fixed in version 2.9.5.6