ZeroHour

CVE-2025-8085

PoC
CVSS 3.1
8.6 high
EPSS
17%p97
Published
()
Modified
Description

The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

Vendors
metaphorcreations
Products
ditty
Ecosystems
WordPress
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.