Ditty (formerly Ditty News Ticker) < 3.0.15 - Reflected Cross-Site Scripting (XSS)
18Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 1.8%
exploitation probability
1.8%top 24% of all CVEs
observed exploitation
nono source reports it
The Ditty (formerly Ditty News Ticker) WordPress plugin before 3.0.15 is affected by a Reflected Cross-Site Scripting (XSS) vulnerability.
Affected products
Unknown · Ditty (formerly Ditty News Ticker)