Impact
The WPComplete plugin for WordPress has a stored cross‑site scripting flaw caused by improper neutralization of user input when generating web pages. An attacker who can inject content through the plugin’s input fields can store malicious scripts that will run when other site visitors load the affected pages. This client‑side injection enables attacks such as session hijacking, defacement, or theft of user data.
Affected Systems
The vulnerability is present in Nexcess WPComplete from the earliest releases through version 2.9.5.4. All WordPress sites that have installed the plugin in any of those versions are affected.
Risk and Exploitability
With a CVSS score of 6.5 the vulnerability is rated medium‑to‑high. No exploit probability score is available and it is not listed in the CISA KEV catalog, indicating no known widespread exploitation. The likely attack vector is through normal web interactions, where an authenticated or unauthenticated user is able to submit content that is later rendered to site visitors.
OpenCVE Enrichment