CVE-2025-15697
EUVD-2025-21092717.09.2026, 06:16
The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone they can induce to submit a crafted request.
Awaiting analysis
This vulnerability is currently awaiting analysis.