PT-2026-94158 · WordPress · Dictionary

CVE-2025-15697

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Dictionary WordPress plugin versions prior to 1.1
Description The plugin fails to escape user input before reflecting it in the responses of several directly accessible scripts. This allows unauthenticated attackers to execute Reflected Cross-Site Scripting (XSS) attacks—a technique where malicious scripts are injected into trusted websites—against users who are induced to submit a specially crafted request.
Recommendations Update the Dictionary WordPress plugin to a version newer than 1.0.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-15697

Affected Products

Dictionary