Dictionary <= 1.0 - Unauthenticated Stored XSS via Direct Dictionary Update
Summary
| CVE | CVE-2026-88792 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-17 06:16:51 UTC |
| Updated | 2026-09-17 06:16:51 UTC |
| Description | The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding or updating dictionary entries, allowing unauthenticated users to store arbitrary web scripts which will execute when a user views an affected entry. |
Risk And Classification
Problem Types: CWE-79 Cross-Site Scripting (XSS)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Unknown | Dictionary | affected 1.0 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/49671af2-af51-44e6-8c0a-3039c50d04e5 | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Pablo González Pérez (en)
CNA: Francisco José Ramírez Vicente (en)
CNA: and Iñigo Sánchez Enciso (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.