CVE-2026-88792: Unknown Dictionary
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding or updating dictionary entries, allowing unauthenticated users to store arbitrary web scripts which will execute when a user views an affected entry.
Affected products
- Unknown Dictionary: up to and including 1.0
Published 2026-09-17. Last modified 2026-09-18.