📦 Ditty

by Metaphorcreations

🔍 What is Ditty?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-8085

HIGH CVSS 8.6 Sep 8, 2025

The Ditty WordPress plugin before version 3.1.58 has an authentication bypass vulnerability in its displayItems endpoint. This allows unauthenticated visitors to make requests to arbitrary URLs, poten...

CVE-2024-9600

MEDIUM CVSS 4.8 Nov 21, 2024

The Ditty WordPress plugin before version 3.1.47 contains a stored cross-site scripting (XSS) vulnerability in its settings. This allows authenticated users with author-level privileges or higher to i...

CVE-2024-6715

MEDIUM CVSS 6.1 Aug 23, 2024

This CVE describes a security regression in the Ditty WordPress plugin where a previously fixed vulnerability was re-introduced in version 3.1.39. The vulnerability allows attackers to perform unautho...

CVE-2024-6710

MEDIUM CVSS 5.4 Aug 5, 2024

The Ditty WordPress plugin before version 3.1.45 contains a cross-site scripting (XSS) vulnerability due to insufficient input sanitization. Users with Contributor-level permissions or higher can inje...

CVE-2024-5575

MEDIUM CVSS 4.7 Jul 13, 2024

The Ditty WordPress plugin before version 3.1.43 contains a stored cross-site scripting (XSS) vulnerability in block settings. This allows authenticated users with author-level privileges or higher to...

CVE-2024-3939

MEDIUM CVSS 5.4 May 27, 2024

The Ditty WordPress plugin before version 3.1.36 contains a stored cross-site scripting (XSS) vulnerability in plugin settings. This allows authenticated administrators to inject malicious scripts tha...