Known CVE
Ditty < 3.1.58 - Server-Side Request Forgery
The plugin lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs. v3.1.57 attempted to fix the issue with a nonce check, however any authenticated users, such as subscriber can retrieve it.
CVE-2025-8085
High2025
cve2025 · ditty-news-ticker · wordpress · wp-plugin · wpscan · wp · metaphorcreations · vuln
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website