HomeDefault status
unaffected
Any version before 3.1.58
affected
Description
The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.
Problem types
CWE-918 Server-Side Request Forgery (SSRF)
Product status
Any version before 3.1.58
Credits
Dmitrii Ignatyev
WPScan
References
wpscan.com/...rability/f42c37bb-1ae0-49ab-bd81-7864dff0fcff/