CVE-2025-50046: WordPress WPComplete plugin <= 2.9.5 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP WPComplete allows Stored XSS. This issue affects WPComplete: from n/a through 2.9.5.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP WPComplete wpcomplete allows Stored XSS.This issue affects WPComplete: from n/a through <= 2.9.5.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-50046?
CVE-2025-50046 is classified as a high-severity Stored Cross-site Scripting (XSS) vulnerability.
How do I fix CVE-2025-50046?
To fix CVE-2025-50046, update StellarWP WPComplete to version 2.9.6 or later.
Who is affected by CVE-2025-50046?
CVE-2025-50046 affects all versions of StellarWP WPComplete up to and including version 2.9.5.
What kind of vulnerability is CVE-2025-50046?
CVE-2025-50046 is an improper neutralization of input during web page generation leading to Stored Cross-site Scripting.
What are the potential consequences of CVE-2025-50046?
If exploited, CVE-2025-50046 could allow attackers to execute arbitrary JavaScript in the context of the affected user's session.