Impact
The vulnerability is a CSRF flaw that allows an attacker, who tricks an authenticated administrator into visiting a crafted URL or form, to inject malicious client‑side code that is stored by the WPComplete plugin. Once stored, the malicious script runs in the browsers of any user who views the affected content, enabling cookie theft, session hijacking, or defacement. The weakness is identified as CWE‑352.
Affected Systems
Liquid Web / StellarWP WPComplete plugin versions up to and including 2.9.5.6. All installations of the plugin from the earliest version through 2.9.5.6 are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 reflects a significant impact when the attacker can target sites with an authenticated user. Because the flaw hinges on CSRF, an attacker only needs to entice an administrator or privileged user to visit a malicious link; no remote code execution or network access is required. The EPSS score is not available, and the weakness is not currently listed in the CISA KEV catalog. However, given the high likelihood of admin users being targeted by phishing or spam links, the risk remains elevated. The documented mitigation is to upgrade to 2.9.5.7 or newer, which removes the vulnerable endpoint.
OpenCVE Enrichment