VYPR
Unrated severityNVD Advisory· Published Sep 8, 2025· Updated Sep 8, 2025

Ditty < 3.1.58 - Unauthenticated SSRF

CVE-2025-8085

Description

The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.