Unrated severityNVD Advisory· Published Sep 17, 2026
CVE-2025-15697
CVE-2025-15697
Description
The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone they can induce to submit a crafted request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=1.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.