SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2025-8085

The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

HIGH 8.6EPSS 17.4%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 17.4%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

CVSS 3.1
8.6 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
EPSS
17.37% probability · 97th percentile
CISA KEV
Not listed
Weakness
CWE-918
Affected
metaphorcreations/ditty
Source
contact@wpscan.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.