Cross-Site Scripting Vulnerability in Terms Dictionary Plugin by Somonator
CVE-2025-39534
7.1HIGH
What is CVE-2025-39534?
The Terms Dictionary plugin by Somonator contains a vulnerability that allows attackers to inject malicious scripts via reflected cross-site scripting (XSS). This occurs due to improper handling of user input during the web page generation process. Affected users of versions up to 1.5.1 are at risk, as this vulnerability can be exploited to execute arbitrary scripts in the context of the user's browser, potentially leading to data theft or session hijacking.
Affected Version(s)
Terms Dictionary 0 <= 1.5.1
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro S Alcântara (Kinorth) (Patchstack Alliance)