Loading vulnerability details…
CVSS v3.1
8.6
EPSS
17.37%
Published
Sep 8, 2025
Modified
Feb 9, 2026
Public PoC / Exploit (2)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:NWeaknesses (CWE)
Affected Products (1)
References (1)