Executive brief
WPComplete is a WordPress plugin used to track course completion and user progress. An unauthenticated cross-site scripting (XSS) vulnerability in versions up to 2.9.5.6 allows attackers to inject malicious scripts that can steal visitor data, hijack user accounts, or redirect site traffic. The vulnerability requires user interaction—such as clicking a malicious link—to be exploited, but poses a significant risk to all website visitors.
Technical details
The vulnerability is a reflected or stored cross-site scripting (XSS) flaw in WPComplete plugin versions ≤ 2.9.5.6 that can be exploited without authentication. The attack vector is network-based and requires user interaction (e.g., a user clicking a crafted link or visiting a malicious page). Successful exploitation allows an attacker to inject arbitrary JavaScript into the page context, enabling session hijacking, credential theft, malware delivery, or redirection attacks. The vulnerability is patched in version 2.9.5.7 and later; immediate update is advised.
Affected products
- StellarWP WPComplete ≤ 2.9.5.6
Timeline
- 2026-08-20: disclosed
- 2026-08-24: advisory
- 2026-08-20: patched: Patched in version 2.9.5.7