← Back to browse · API

CVE-2025-8085

Severity
HIGH
CVSS
8.6
EPSS
0.17371
Risk score
40.48
CISA KEV
No
PoC
No
Published
2025-09-08
Modified
2025-09-08
First seen
2026-08-07
Aliases
EUVD-2025-27111, GHSA-5W55-FGG7-M5GX
Products
metaphorcreations:Ditty 0 <3.1.58
Sources
euvd EUVD-2025-27111

Description

The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

References