Metaphorcreations

Ditty

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 23.09.2026 18:14:28
  • Zuletzt bearbeitet 23.09.2026 19:39:08

Contributor Cross Site Scripting (XSS) in Ditty <= 3.1.69 versions.

  • EPSS 0.15%
  • Veröffentlicht 21.09.2026 14:29:21
  • Zuletzt bearbeitet 25.09.2026 18:17:33

Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that allows authenticated users with Author-level privileges or higher to inject arbitrary HTML elements by supplying malicious wrapper at...

  • EPSS 0.28%
  • Veröffentlicht 27.08.2026 09:00:09
  • Zuletzt bearbeitet 28.08.2026 15:09:00

Subscriber Broken Access Control in Ditty <= 3.1.67 versions.

  • EPSS 0.28%
  • Veröffentlicht 23.07.2026 11:17:53
  • Zuletzt bearbeitet 23.07.2026 15:17:03

Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.

  • EPSS 0.19%
  • Veröffentlicht 26.09.2025 09:15:36
  • Zuletzt bearbeitet 23.04.2026 15:34:13

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in metaphorcreations Ditty ditty-news-ticker allows Stored XSS.This issue affects Ditty: from n/a through <= 3.1.58.

Exploit
  • EPSS 17.37%
  • Veröffentlicht 08.09.2025 06:00:04
  • Zuletzt bearbeitet 30.09.2026 23:10:00

The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

Exploit
  • EPSS 0.31%
  • Veröffentlicht 15.05.2025 20:15:39
  • Zuletzt bearbeitet 10.06.2025 13:31:40

The Ditty WordPress plugin before 3.1.52 does not sanitise and escape some of its settings, which could allow high privilege users such as author to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (...

  • EPSS 0.42%
  • Veröffentlicht 09.12.2024 13:15:30
  • Zuletzt bearbeitet 29.04.2026 10:16:24

Missing Authorization vulnerability in metaphorcreations Ditty ditty-news-ticker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ditty: from n/a through <= 3.1.24.

Exploit
  • EPSS 0.37%
  • Veröffentlicht 21.11.2024 11:15:37
  • Zuletzt bearbeitet 15.05.2025 16:04:05

The Ditty WordPress plugin before 3.1.47 does not sanitise and escape some of its settings, which could allow high privilege users such as author to perform Stored Cross-Site Scripting attacks.

Exploit
  • EPSS 0.35%
  • Veröffentlicht 23.08.2024 06:15:04
  • Zuletzt bearbeitet 17.05.2025 02:08:32

The Ditty WordPress plugin before 3.1.46 re-introduced a previously fixed security issue (https://wpscan.com/vulnerability/80a9eb3a-2cb1-4844-9004-ba2554b2d46c/) in v3.1.39