Impact
The Dictionary WordPress plugin, version 1.0 and earlier, does not escape user input before echoing it back in several publicly accessible scripts. An unauthenticated attacker can send a crafted request containing malicious script content to any user who visits the site, causing the script to execute in the victim’s browser. Such vectors allow attackers to hijack user sessions, steal cookies, redirect users, or deface pages. The weakness is a classic input validation flaw (CWE‑79).
Affected Systems
WordPress sites that have installed the Dictionary plugin, version 1.0 or older. No other version numbers are known to be affected, and the plugin is provided by the vendor under the name Dictionary.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity for a reflected XSS. The EPSS score of less than 1% suggests that real‑world exploitation, while plausible, is considered rare at this time. The vulnerability is not listed in CISA’s KEV catalog, meaning no known widespread use has been reported. Attackers can exploit the flaw by directing any internet user to a crafted URL that includes malicious parameters; no authentication or privileged access is required.
OpenCVE Enrichment