CVE-2025-8085
EUVD-2025-2711108.09.2025, 06:15
The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| metaphorcreations | ditty | 𝑥 < 3.1.58 |
𝑥
= Vulnerable software versions