Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27111 | The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs. |
Mon, 09 Feb 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Metaphorcreations
Metaphorcreations ditty |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:metaphorcreations:ditty:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Metaphorcreations
Metaphorcreations ditty |
Mon, 08 Sep 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 08 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Mon, 08 Sep 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs. | |
| Title | Ditty < 3.1.58 - Unauthenticated SSRF | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-09-08T18:17:25.816Z
Reserved: 2025-07-23T13:48:45.718Z
Link: CVE-2025-8085
Updated: 2025-09-08T18:17:09.906Z
Status : Analyzed
Published: 2025-09-08T06:15:34.833
Modified: 2026-02-09T18:19:09.703
Link: CVE-2025-8085
No data.
OpenCVE Enrichment
Updated: 2025-09-08T15:17:22Z
EUVD