Executive brief
The Dictionary WordPress plugin (through version 1.0) contains a critical flaw that allows anyone—including unauthenticated visitors—to inject malicious scripts into dictionary entries. When legitimate users view these entries, the injected scripts execute in their browsers, potentially enabling account takeover, session hijacking, or theft of sensitive information. This affects any WordPress site using the vulnerable plugin with default file permissions.
Technical details
This is an unauthenticated stored cross-site scripting (XSS) vulnerability (CWE-79) in the Dictionary WordPress plugin through version 1.0. The plugin fails to implement authorization checks, input sanitization, or output escaping when adding or updating dictionary entries. An attacker can directly write malicious JavaScript payloads to the plugin's data file (which is typically writable by PHP under default file ownership), and these scripts execute in the context of any user viewing the affected entry. Exploitation does not require authentication or user interaction beyond viewing a compromised entry. No patch has been publicly released as of the advisory date.
Affected products
- WordPress Dictionary through 1.0
Timeline
- 2026-09-15: disclosed: Publicly published by WPScan
- 2026-09-17: advisory: CVE-2026-88792 published