CVE-2026-88792 PUBLISHED

Dictionary <= 1.0 - Unauthenticated Stored XSS via Direct Dictionary Update

Assigner: WPScan
Reserved: 10.09.2026 Published: 17.09.2026 Updated: 17.09.2026

The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding or updating dictionary entries, allowing unauthenticated users to store arbitrary web scripts which will execute when a user views an affected entry.

Product Status

Vendor Unknown
Product Dictionary
Versions Default: unknown
  • affected from 0 to 1.0 (incl.)

Credits

  • Pablo González Pérez finder
  • Francisco José Ramírez Vicente finder
  • and Iñigo Sánchez Enciso finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE