---
id: CVE-2025-8085
title: >-
  The Ditty  WordPress plugin before 3.1.58 lacks authorization and
  authentication for requests to its displayItems endpoint, allowing
  unauthenticated visitors to make requests to arbitrary URLs.
summary: >-
  The Ditty  WordPress plugin before 3.1.58 lacks authorization and
  authentication for requests to its displayItems endpoint, allowing
  unauthenticated visitors to make requests to arbitrary URLs.
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-918
vendor: metaphorcreations
product: ditty
affected:
  - ditty < 3.1.58
patched:
  - ditty 3.1.58
published: '2025-09-08'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-8085'
references:
  - url: 'https://wpscan.com/vulnerability/f42c37bb-1ae0-49ab-bd81-7864dff0fcff/'
    label: contact@wpscan.com
tags:
  - nvd
  - exploit-available
epss: 0.1819
epssPercentile: 0.97121
exploits:
  nuclei:
    - CVE-2025-8085
  checkedAt: '2026-09-30T23:30:07.495Z'
exploitAvailable: true
ingestedAt: '2026-09-30T23:29:32.372Z'
---

## Overview

The Ditty  WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

## Affected

- `ditty < 3.1.58`

## Remediation

Upgrade past the affected range:

- `ditty 3.1.58`
