Unrated severityNVD Advisory· Published Sep 8, 2025· Updated Sep 8, 2025
Ditty < 3.1.58 - Unauthenticated SSRF
CVE-2025-8085
Description
The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.
Affected products
1- Range: <3.1.58
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/f42c37bb-1ae0-49ab-bd81-7864dff0fcff/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.