Critical
Low
Medium

CVE-2025-8085

Overview

The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

Critical
Low
Medium
No items found.

Package:

Impact:

Fix:

Year:

CVSS:

Severity:

Affected Components

Location

Stop the waste.
Protect your environment with Kodem.

Get a personalized demo
Get a personalized demo