PT-2026-94170 · WordPress · Dictionary

CVE-2026-88792

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dictionary WordPress plugin versions prior to 1.1
Description Lack of authorization, sanitization, and escaping when adding or updating dictionary entries allows unauthenticated users to perform a Stored Cross-Site Scripting (XSS) attack. This occurs when arbitrary web scripts are stored and subsequently executed in the browser of any user who views the affected entry.
Recommendations Update the Dictionary WordPress plugin to a version newer than 1.0.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-88792

Affected Products

Dictionary