Cross-site Scripting Vulnerability in StellarWP WPComplete Plugin
CVE-2025-58974
6.5MEDIUM
What is CVE-2025-58974?
An improper neutralization of input during web page generation leading to a Cross-site Scripting (XSS) vulnerability affects the WPComplete plugin by StellarWP. This flaw allows for stored XSS attacks, which could enable unauthorized users to execute malicious scripts in the context of a victim's browser session, potentially compromising sensitive information and site integrity.
Affected Version(s)
WPComplete <= 2.9.5.2