The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone they can induce to submit a crafted request.
https://wpscan.com/vulnerability/b0d12b0d-4717-4854-8911-2a0e60eed515/