CVE-2026-66599: WordPress WPComplete plugin <= 2.9.5.6 - Cross Site Scripting (XSS) vulnerability
Published Aug 24, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions.
Affected Software
1 affected component
WPComplete<=2.9.5.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WPComplete pluginto a version that resolves this vulnerability.Fixed in 2.9.5.7
Event History
Aug 24, 2026
CVE Published
via MITRE·11:39 AM
Data Sourced
via MITRE·11:39 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress account or prior access to the site. Exploitation still requires user interaction, as indicated by the UI:R vector.
2
What versions should be treated as affected?
WPComplete versions 2.9.5.6 and earlier are identified as affected. The provided data does not identify a fixed version.
3
What impact could successful exploitation have?
The vulnerability can allow cross-site scripting in a victim's browser. The supplied CVSS vector indicates low confidentiality, integrity, and availability impact, with scope changed.