← back
CVE-2025-8085highobserved exploitation

Ditty < 3.1.58 - Unauthenticated SSRF

63Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 8.6epss 17%
from disclosure to weapon
Published on NVDSep 8
VulnCheck+67d
exploitation probability
17%top 3% of all CVEs
observed exploitation
yesVulnCheck
The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Affected products
Unknown · Ditty