8.6
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 4.0
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.
Affected (1)
Products: Metaphorcreations: Ditty
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.1.58 |
References (1)
Source: contact@wpscan.com
ExploitThird Party Advisory
Timeline
No history available yet.