Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 17 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Thu, 17 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding or updating dictionary entries, allowing unauthenticated users to store arbitrary web scripts which will execute when a user views an affected entry. | |
| Title | Dictionary <= 1.0 - Unauthenticated Stored XSS via Direct Dictionary Update | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-17T12:28:14.877Z
Reserved: 2026-09-10T08:08:20.286Z
Link: CVE-2026-88792
Updated: 2026-09-17T12:11:26.754Z
Status : Received
Published: 2026-09-17T06:16:51.990
Modified: 2026-09-17T13:16:57.383
Link: CVE-2026-88792
No data.
OpenCVE Enrichment
No data.