CVE-2025-15697: Dictionary <= 1.0 - Reflected XSS via Multiple Parameters
The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone they can induce to submit a crafted request.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue, and who is at risk?
An attacker does not need to authenticate to send a crafted request. The practical impact is on users who can be induced to submit that request and whose browser renders the reflected response.
Are default or publicly reachable installations affected?
The affected scripts are described as directly accessible, so no authenticated WordPress access is required for exploitation. The available information does not identify any configuration prerequisite or mitigation setting.
How can I determine whether my site is affected?
Sites using the Dictionary WordPress plugin at version 1.0 or earlier are within the stated affected range. The issue involves multiple parameters handled by directly accessible plugin scripts.