Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ditty HIGH 8.6
CVE-2025-8085EPSS 17%

The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated …

Fix: 3.1.58+
Fix from $1,950 2025-09-08
Ditty MEDIUM 6.1
CVE-2024-6715

The Ditty WordPress plugin before 3.1.46 re-introduced a previously fixed security issue (https://wpscan.com/vulnerability/80a9eb3a-2cb1-4844-9004-b…

Fix: 3.1.46+
Fix from $1,600 2024-08-23
Ditty MEDIUM 5.4
CVE-2024-6710

The Ditty WordPress plugin before 3.1.45 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to …

Fix: 3.1.46+
Fix from $1,600 2024-08-05
Ditty MEDIUM 5.4
CVE-2024-3939

The Ditty WordPress plugin before 3.1.36 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Fix: 3.1.36+
Fix from $1,600 2024-05-27
Ditty MEDIUM 6.1
CVE-2023-4148

The Ditty WordPress plugin before 3.1.25 does not sanitise and escape some parameters and generated URLs before outputting them back in attributes, l…

Fix: 3.1.25+
Fix from $1,600 2023-09-25
Ditty MEDIUM 5.4
CVE-2023-23874

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Metaphor Creations Ditty plugin <= 3.0.32 versions.

Fix: 3.0.33+
Fix from $1,600 2023-05-03
Post Duplicator MEDIUM 6.1
CVE-2016-15027

A vulnerability was found in meta4creations Post Duplicator Plugin 2.18 on WordPress. It has been classified as problematic. Affected is the function…

Patch available
Fix from $1,600 2023-02-20
Post Duplicator MEDIUM 5.4
CVE-2021-33852

A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for th…

No fix yet
Fix from $1,600 2022-03-10
Ditty MEDIUM 6.1
CVE-2022-0533

The Ditty (formerly Ditty News Ticker) WordPress plugin before 3.0.15 is affected by a Reflected Cross-Site Scripting (XSS) vulnerability.

Fix: 3.0.15+
Fix from $1,600 2022-03-07