CVE-2025-15697
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Sep 17, 2026
Vendor
unknown
Description
The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone they can induce to submit a crafted request.