CVE-2025-15697 PUBLISHED

Dictionary <= 1.0 - Reflected XSS via Multiple Parameters

Assigner: WPScan
Reserved: 10.09.2026 Published: 17.09.2026 Updated: 17.09.2026

The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone they can induce to submit a crafted request.

Product Status

Vendor Unknown
Product Dictionary
Versions Default: unknown
  • affected from 0 to 1.0 (incl.)

Credits

  • Hassan Khan Yusufzai - Splint3r7 finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE