Impact
The vulnerability described allows an attacker to inject arbitrary client‑side script into pages served by the WordPress WPComplete plugin. Because the plugin does not properly escape or validate input, any user able to access the plugin’s functionality can create requests that result in scripts being rendered in the victim’s browser. The weakness is identified as an XSS flaw (CWE‑79).
Affected Systems
WordPress sites that have the WPComplete plugin version 2.9.5.6 or earlier from Liquid Web / StellarWP are affected. No other versions or unrelated WordPress plugins are listed as impacted. Updates to 2.9.5.7 or later address the issue.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity. The EPSS score is not available, so the likelihood of exploitation cannot be estimated from public data. The vulnerability is not listed in CISA's KEV catalog, suggesting no publicly known exploited cases at the time of reporting. According to the description, the flaw is unauthenticated, meaning an attacker can craft requests without needing to log in. The attack likely involves sending malicious input to the plugin’s endpoints, making it a remote, low‑barrier vector.
OpenCVE Enrichment