---
id: CVE-2026-88792
title: >-
  The Dictionary WordPress plugin through 1.0 does not have authorisation,
  sanitisation or escaping in place when adding or updating dictionary entries,
  allowing unauthenticated users to store arbitrary web scripts which will
  execute when …
summary: >-
  The Dictionary WordPress plugin through 1.0 does not have authorisation,
  sanitisation or escaping in place when adding or updating dictionary entries,
  allowing unauthenticated users to store arbitrary web scripts which will
  execute when …
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
product: Dictionary
affected:
  - Dictionary <= 1.0
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:08:32.830'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88792'
references:
  - url: 'https://wpscan.com/vulnerability/49671af2-af51-44e6-8c0a-3039c50d04e5/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00505
epssPercentile: 0.40688
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-17T12:12:31.979583Z'
ingestedAt: '2026-09-17T06:12:17.974Z'
---

## Overview

The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding or updating dictionary entries, allowing unauthenticated users to store arbitrary web scripts which will execute when a user views an affected entry.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
