PT-2025-36441 · WordPress · Ditty Wordpress Plugin
Dmitry Ignatyev
·
Published
2025-09-08
·
Updated
2026-02-16
·
CVE-2025-8085
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ditty WordPress plugin versions prior to 3.1.58
Description
The Ditty WordPress plugin before version 3.1.58 has a flaw where the
displayItems endpoint does not require authorization or authentication. This allows unauthenticated visitors to send requests to arbitrary URLs. This is a Server-Side Request Forgery (SSRF) issue, meaning an attacker can make the server fetch internal URLs. The vulnerable API endpoint is /wp-json/dittyeditor/v1/displayItems. The lack of proper authorization and filtering of the source url allows attackers to exploit this vulnerability. This could potentially allow attackers to perform internal network reconnaissance or access resources behind firewalls.Recommendations
Update the Ditty WordPress plugin to version 3.1.58 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ditty Wordpress Plugin