plugin

Wpcomplete Vulnerabilities

10 known security issues reported for the Wpcomplete WordPress plugin. Most recent disclosed Aug 20, 2026.

1 high 6 medium

Running Wpcomplete on your site? Check whether your installed version is affected.

Scan your site free

WPComplete <= 2.9.5.6 - Unauthenticated Stored Cross-Site Scripting

high

The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9.5.6. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a u...

CVSS:
7.2
Affected:
up to 2.9.5.6
Fixed in:
2.9.5.7
Disclosed:
Aug 20, 2026

CVE-2026-66599 on NVD →

WPComplete <= 2.9.5.5 - Missing Authorization

medium

The WPComplete plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.9.5.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.9.5.5
Fixed in:
2.9.5.6
Disclosed:
Jun 26, 2026

CVE-2026-57661 on NVD →

WPComplete <= 2.9.5.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that...

CVSS:
6.4
Affected:
up to 2.9.5.4
Fixed in:
2.9.5.5
Disclosed:
May 29, 2026

CVE-2026-42750 on NVD →

WPComplete <= 2.9.5.3 - Missing Authorization

medium

The WPComplete plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the delete_button() function in all versions up to, and including, 2.9.5.3. This makes it possible for unauthenticated attackers to delete buttons.

CVSS:
5.3
Affected:
up to 2.9.5.3
Fixed in:
2.9.5.4
Disclosed:
Oct 24, 2025

CVE-2025-49906 on NVD →

WPComplete [wpcomplete] <= 2.9.5.3 (unfixed)

unknown

[en] Missing Authorization vulnerability in StellarWP WPComplete wpcomplete allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPComplete: from n/a through <= 2.9.5.3.

Affected:
up to 2.9.5.3
Fix:
No patched version reported
Disclosed:
Oct 22, 2025

CVE-2025-49906 on NVD →

WPComplete <= 2.9.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages tha...

CVSS:
6.4
Affected:
up to 2.9.5.2
Fixed in:
2.9.5.3
Disclosed:
Sep 22, 2025

CVE-2025-58974 on NVD →

WPComplete [wpcomplete] <= 2.9.5 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP WPComplete allows Stored XSS. This issue affects WPComplete: from n/a through 2.9.5.

Affected:
up to 2.9.5
Fix:
No patched version reported
Disclosed:
Jun 20, 2025

CVE-2025-50046 on NVD →

WPComplete <= 2.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...

CVSS:
6.4
Affected:
up to 2.9.5
Fixed in:
2.9.5.1
Disclosed:
Jun 19, 2025

CVE-2025-50046 on NVD →

WPComplete [wpcomplete] < 2.9.5

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in iThemes WPComplete plugin <= 2.9.2 versions.

Affected:
up to 2.9.5
Fixed in:
2.9.5
Disclosed:
Mar 28, 2023

CVE-2022-45825 on NVD →

WPComplete <= 2.9.4 - Reflected Cross-Site Scripting

medium

The WPComplete plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in versions up to, and including, 2.9.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute i...

CVSS:
6.1
Affected:
up to 2.9.5
Fixed in:
2.9.5
Disclosed:
Jan 27, 2023

CVE-2022-45825 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database