Description
Missing Authorization vulnerability in StellarWP WPComplete wpcomplete allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPComplete: from n/a through <= 2.9.5.3.
Published: 2025-10-22
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the StellarWP WPComplete plugin. An attacker can access restricted functions that should be protected by access control lists. This flaw is categorized as CWE‑862 and could allow unauthorized modification of plugin settings, execution of privileged actions, or other sensitive operations that are not meant to be available to all users.

Affected Systems

The issue applies to the StellarWP WPComplete installation from the earliest version up to and including 2.9.5.3. Users running any of these versions on a WordPress site are affected. No older or newer releases are known to contain the flaw.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, while the EPSS score of less than 1% signals a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The most likely scenario involves an attacker who can reach the plugin’s endpoints, likely through a web request, and bypasses normal ACL checks to gain unauthorized access to protected functions. Direct exploitation would require the attacker to have network access to the WordPress instance, but no authenticated session is explicitly required according to the description.

Generated by OpenCVE AI on April 30, 2026 at 05:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest version of the StellarWP WPComplete plugin that contains the access control fix.
  • Apply role‑based access restrictions to ensure only authorized administrators can reach the plugin’s management URLs, and block or disable any public routes associated with it.
  • Validate the plugin’s configuration to confirm that ACL checks are enforced on all privileged actions, and use a web application firewall or similar controls to block attempts to access restricted functions.

Generated by OpenCVE AI on April 30, 2026 at 05:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 23 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 22 Oct 2025 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 22 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in StellarWP WPComplete wpcomplete allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPComplete: from n/a through <= 2.9.5.3.
Title WordPress WPComplete plugin <= 2.9.5.3 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:07.508Z

Reserved: 2025-06-11T16:06:50.723Z

Link: CVE-2025-49906

cve-icon Vulnrichment

Updated: 2025-10-22T20:27:03.682Z

cve-icon NVD

Status : Deferred

Published: 2025-10-22T15:15:36.503

Modified: 2026-04-27T20:16:16.187

Link: CVE-2025-49906

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T06:00:12Z

Weaknesses