CVE-2025-15697: Unknown Dictionary
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone they can induce to submit a crafted request.
Affected products
- Unknown Dictionary: up to and including 1.0
Published 2026-09-17. Last modified 2026-09-18.