Nexcess · Wpcomplete · CVE-2026-57661
**Name of the Vulnerable Software and Affected Versions**
WPComplete versions prior to 2.9.5.6
**Description**
The WPComplete plugin for WordPress contains a broken access control issue caused by a missing capability check in a function. This allows authenticated users with subscriber-level permissions or higher to perform unauthorized actions.
**Recommendations**
Update WPComplete to a version newer than 2.9.5.5.