CVE-2025-8085: Metaphorcreations Ditty

High severity, CVSS 8.6. EPSS: 19.6% chance of exploitation in the next 30 days.

The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

Affected products

Published 2025-09-08. Last modified 2026-09-30.