The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone they can induce to submit a crafted request.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 17 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone they can induce to submit a crafted request. | |
| Title | Dictionary <= 1.0 - Reflected XSS via Multiple Parameters | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-17T06:00:09.305Z
Reserved: 2026-09-10T08:08:22.186Z
Link: CVE-2025-15697
No data.
Status : Received
Published: 2026-09-17T06:16:50.053
Modified: 2026-09-17T06:16:50.053
Link: CVE-2025-15697
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.