Impact
The WPComplete plugin suffers from stored cross‑site scripting when an empty attribute is included in a shortcode. The plugin fails to fully escape this attribute, allowing an authenticated user with contributor permission or higher to embed arbitrary JavaScript into post or page content. When a visitor loads a page containing the injected shortcode, the script executes in the visitor’s browser, providing client‑side code execution. This flaw is classified as CWE‑79, and the CVSS score of 6.4 reflects its moderate severity.
Affected Systems
The problem exists in the StellarWP WPComplete plugin, versions 2.9.9.0 and older. It is limited to the premium (pro) edition of the plugin and requires that a contributor or higher level user create or edit content that includes the shortcode. Any WordPress site running a vulnerable WPComplete pro version while capable of running shortcodes is at risk.
Risk and Exploitability
An attacker with contributor or higher privileges can construct a payload that uses the empty attribute in a WPComplete shortcode and publish or edit content. The malicious script is then stored in the database and executed whenever the affected page is rendered to a visitor. The vulnerability provides client‑side execution only; it does not give direct access to the server or bypass authentication. Because the flaw requires authenticated contributor‑level access, exploitation is limited to users who have legitimate permissions or to attackers who have compromised such credentials. The EPSS is unavailable and the issue is not listed in the CISA KEV catalog.
OpenCVE Enrichment