---
id: CVE-2025-15697
title: >-
  The Dictionary WordPress plugin through 1.0 does not escape user input before
  reflecting it back in the responses of several directly accessible scripts,
  allowing unauthenticated attackers to perform Reflected Cross-Site Scripting
  attack…
summary: >-
  The Dictionary WordPress plugin through 1.0 does not escape user input before
  reflecting it back in the responses of several directly accessible scripts,
  allowing unauthenticated attackers to perform Reflected Cross-Site Scripting
  attack…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'
cwe:
  - CWE-79
product: Dictionary
affected:
  - Dictionary <= 1.0
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:08:32.830'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15697'
references:
  - url: 'https://wpscan.com/vulnerability/b0d12b0d-4717-4854-8911-2a0e60eed515/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00164
epssPercentile: 0.04888
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T12:14:22.380427Z'
ingestedAt: '2026-09-17T06:12:17.977Z'
---

## Overview

The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone they can induce to submit a crafted request.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
