CVE-2026-94461
- EPSS 0.17%
- Veröffentlicht 23.09.2026 18:14:28
- Zuletzt bearbeitet 23.09.2026 19:39:08
Contributor Cross Site Scripting (XSS) in Ditty <= 3.1.69 versions.
CVE-2026-93339
- EPSS 0.15%
- Veröffentlicht 21.09.2026 14:29:21
- Zuletzt bearbeitet 25.09.2026 18:17:33
Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that allows authenticated users with Author-level privileges or higher to inject arbitrary HTML elements by supplying malicious wrapper at...
CVE-2026-81274
- EPSS 0.28%
- Veröffentlicht 27.08.2026 09:00:09
- Zuletzt bearbeitet 28.08.2026 15:09:00
Subscriber Broken Access Control in Ditty <= 3.1.67 versions.
CVE-2026-27355
- EPSS 0.28%
- Veröffentlicht 23.07.2026 11:17:53
- Zuletzt bearbeitet 23.07.2026 15:17:03
Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.
CVE-2025-60105
- EPSS 0.19%
- Veröffentlicht 26.09.2025 09:15:36
- Zuletzt bearbeitet 23.04.2026 15:34:13
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in metaphorcreations Ditty ditty-news-ticker allows Stored XSS.This issue affects Ditty: from n/a through <= 3.1.58.
CVE-2025-8085
- EPSS 17.37%
- Veröffentlicht 08.09.2025 06:00:04
- Zuletzt bearbeitet 30.09.2026 23:10:00
The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.
CVE-2024-13357
- EPSS 0.31%
- Veröffentlicht 15.05.2025 20:15:39
- Zuletzt bearbeitet 10.06.2025 13:31:40
The Ditty WordPress plugin before 3.1.52 does not sanitise and escape some of its settings, which could allow high privilege users such as author to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (...
CVE-2023-47764
- EPSS 0.42%
- Veröffentlicht 09.12.2024 13:15:30
- Zuletzt bearbeitet 29.04.2026 10:16:24
Missing Authorization vulnerability in metaphorcreations Ditty ditty-news-ticker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ditty: from n/a through <= 3.1.24.
CVE-2024-9600
- EPSS 0.37%
- Veröffentlicht 21.11.2024 11:15:37
- Zuletzt bearbeitet 15.05.2025 16:04:05
The Ditty WordPress plugin before 3.1.47 does not sanitise and escape some of its settings, which could allow high privilege users such as author to perform Stored Cross-Site Scripting attacks.
CVE-2024-6715
- EPSS 0.35%
- Veröffentlicht 23.08.2024 06:15:04
- Zuletzt bearbeitet 17.05.2025 02:08:32
The Ditty WordPress plugin before 3.1.46 re-introduced a previously fixed security issue (https://wpscan.com/vulnerability/80a9eb3a-2cb1-4844-9004-ba2554b2d46c/) in v3.1.39