The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.
References
| Link | Resource |
|---|---|
| https://wpscan.com/vulnerability/f42c37bb-1ae0-49ab-bd81-7864dff0fcff/ | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-09-08 06:15
Updated : 2026-06-17 10:06
NVD link : CVE-2025-8085
Mitre link : CVE-2025-8085
CVE.ORG link : CVE-2025-8085
JSON object : View
Products Affected
metaphorcreations
- ditty
CWE
CWE-918
Server-Side Request Forgery (SSRF)
