Description
Cross-Site Request Forgery (CSRF) vulnerability in Liquid Web / StellarWP WPComplete wpcomplete allows Stored XSS.This issue affects WPComplete: from n/a through 2.9.5.6.
Published: 2026-10-08
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross‑site scripting via CSRF
Action: Immediate patch
AI Analysis

Impact

The vulnerability is a CSRF flaw that allows an attacker, who tricks an authenticated administrator into visiting a crafted URL or form, to inject malicious client‑side code that is stored by the WPComplete plugin. Once stored, the malicious script runs in the browsers of any user who views the affected content, enabling cookie theft, session hijacking, or defacement. The weakness is identified as CWE‑352.

Affected Systems

Liquid Web / StellarWP WPComplete plugin versions up to and including 2.9.5.6. All installations of the plugin from the earliest version through 2.9.5.6 are vulnerable.

Risk and Exploitability

The CVSS score of 7.1 reflects a significant impact when the attacker can target sites with an authenticated user. Because the flaw hinges on CSRF, an attacker only needs to entice an administrator or privileged user to visit a malicious link; no remote code execution or network access is required. The EPSS score is not available, and the weakness is not currently listed in the CISA KEV catalog. However, given the high likelihood of admin users being targeted by phishing or spam links, the risk remains elevated. The documented mitigation is to upgrade to 2.9.5.7 or newer, which removes the vulnerable endpoint.

Generated by OpenCVE AI on October 8, 2026 at 14:42 UTC.

Remediation

Vendor Solution

Update the WordPress WPComplete plugin to the latest available version (at least 2.9.5.7).


OpenCVE Recommended Actions

  • Update the WPComplete plugin to version 2.9.5.7 or newer.
  • If an update is not immediately possible, deactivate the plugin to stop the CSRF vector.
  • Scan the site for any injected scripts or suspicious code and remove them.

Generated by OpenCVE AI on October 8, 2026 at 14:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Liquid Web / StellarWP WPComplete wpcomplete allows Stored XSS.This issue affects WPComplete: from n/a through 2.9.5.6.
Title WordPress WPComplete plugin <= 2.9.5.6 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-08T14:12:00.074Z

Reserved: 2026-07-27T09:50:27.375Z

Link: CVE-2026-66479

cve-icon Vulnrichment

Updated: 2026-10-08T14:11:55.584Z

cve-icon NVD

Status : Deferred

Published: 2026-10-08T13:17:18.707

Modified: 2026-10-08T17:24:11.230

Link: CVE-2026-66479

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T14:45:17Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)