PT-2025-36441 · WordPress · Ditty Wordpress Plugin

Dmitry Ignatyev

·

Published

2025-09-08

·

Updated

2025-09-08

·

CVE-2025-8085

CVSS v3.1
8.6
VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

**Name of the Vulnerable Software and Affected Versions:**

Ditty WordPress plugin versions prior to 3.1.58

**Description:**

The Ditty WordPress plugin is susceptible to an unauthenticated Server-Side Request Forgery (SSRF) condition. This flaw resides in the `wp-json/dittyeditor/v1/displayItems` API endpoint, which does not enforce proper authorization. This allows unauthenticated attackers to make requests to arbitrary URLs, potentially enabling internal network reconnaissance or access to protected resources.

**Recommendations:**

Update Ditty WordPress plugin to version 3.1.58 or later.

Exploit

Fix

Related Identifiers

CVE-2025-8085

Affected Products

Ditty Wordpress Plugin