Executive brief
The WPComplete WordPress plugin for course completion tracking allows authenticated site contributors to inject malicious scripts into web pages via a shortcode attribute. When other users view an affected page, the injected script executes in their browsers, potentially stealing credentials or performing unauthorized actions. This vulnerability requires the premium version of the plugin.
Technical details
A stored cross-site scripting vulnerability exists in the WPComplete plugin due to insufficient input sanitization and output escaping of the 'empty' shortcode attribute. Authenticated attackers with contributor-level access or higher can inject arbitrary JavaScript that persists on pages. The vulnerability affects the premium version up to 2.9.9.0.
Affected products
- WPComplete WPComplete up to and including 2.9.9.0
Timeline
- 2026-09-19: disclosed