Sceawere

Vulnerability Detail

CVE-2026-66479UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WPComplete CSRF Stored XSS

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
4h ago
Vendor
Liquid Web / StellarWP
Product
WPComplete
Attack Type
Cross-Site Request Forgery (CSRF)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Cross-Site Request Forgery (CSRF) vulnerability in Liquid Web / StellarWP WPComplete wpcomplete allows Stored XSS.This issue affects WPComplete: from n/a through 2.9.5.6.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-08T13:17:18.707Z",
  "pubdate": "2026-10-08T13:17:18.707Z",
  "executiveSummary": "The WPComplete plugin for WordPress, developed by Liquid Web / StellarWP, is affected by a Cross-Site Request Forgery (CSRF) vulnerability that facilitates Stored Cross-Site Scripting (XSS).\nThis vulnerability exists within versions ranging from n/a through 2.9.5.6, potentially allowing an unauthenticated or authenticated attacker to trick a legitimate administrator into performing unauthorized actions.\nBy leveraging the CSRF vector, an attacker can force the application to execute malicious scripts stored in the database.\nSuccessful exploitation results in Stored XSS, enabling the attacker to execute arbitrary JavaScript in the context of the administrator's session.\nThis can lead to full administrative account compromise, unauthorized content modification, redirection of users, or the theft of sensitive session cookies.\nThe risk implication is high, as it requires only the user to interact with a crafted malicious link or page while authenticated to the WordPress dashboard to trigger the payload.",
  "technicalDetails": "The root cause of this vulnerability lies in the improper handling of CSRF tokens for administrative actions within the WPComplete plugin, which is subsequently leveraged to inject malicious script content that is stored by the application.\nThe vulnerability occurs because the plugin fails to implement sufficient nonce validation or CSRF protection mechanisms on sensitive endpoints that manage configuration or user-defined content.\nBecause these endpoints lack appropriate origin validation and token-based integrity checks, an attacker can craft an HTTP request that, when executed in the victim's browser, performs an authorized action without the user's consent or knowledge.\nIn this specific attack flow, the attacker constructs a malicious payload containing an XSS vector—typically obfuscated JavaScript or HTML tags—and embeds it within a CSRF-based request targeting a WPComplete administrative function.\nThe attacker then lures an authenticated administrator to visit a malicious website or click a crafted link containing this request. Since the administrator's browser is already authenticated to the WordPress instance, the browser automatically includes the necessary session cookies with the forged request.\nThe application processes the request, believing it to be a legitimate action performed by the administrator. Consequently, the malicious script payload is submitted to and stored within the WordPress database.\nOnce stored, the malicious script is rendered whenever the administrator—or potentially other users, depending on the scope—views the compromised component within the WordPress dashboard.\nThe execution of this stored script occurs within the victim's browser session, granting the attacker the same permissions as the administrator. The post-exploitation impact includes the ability to perform actions such as creating new administrative users, modifying existing plugin settings, injecting additional malicious scripts, or exfiltrating sensitive session data.\nThe attack vector is effective because it bypasses the need for the attacker to have direct access to the WordPress dashboard, relying instead on the social engineering of an authenticated user to perform the actions on their behalf."
}
CVE-2026-66479: WPComplete CSRF Stored XSS (HIGH Severity, CVSS: 7.1) | Sceawere