Impact
The Dictionary WordPress plugin leads unauthenticated users to store arbitrary web scripts when adding or updating entries because authorisation, sanitisation or escaping is missing. This flaw permits stored XSS that triggers when any user views the affected entry, enabling session hijacking, defacement or malware delivery.
Affected Systems
WordPress sites that use the Dictionary plugin up to version 1.0 are vulnerable. The issue applies to any installation where the plugin’s update functionality is publicly accessible without administrative permission.
Risk and Exploitability
The vulnerability scores a CVSS of 8.8, reflecting high impact, while an EPSS score of less than 1% suggests a low likelihood of discovery or exploitation at this time. It is not listed in CISA KEV. Exploitation requires unauthenticated access to the dictionary update endpoint; once a malicious script is stored, it runs in the context of any user that views the entry, producing severe cross‑site scripting damage.
OpenCVE Enrichment