Loading market data...
← Back to CVE feed

CVE-2025-15697

HIGH CVSS 7.1 View on NVD ↗

Description

The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone they can induce to submit a crafted request.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Published: Sep 17, 2026 06:16 UTC Modified: Sep 17, 2026 13:16 UTC