← Vulnerability feed

Vulnerability record · CVE-2023-23874 · published 3 May 2023

CVE-2023-23874: Metaphorcreations ditty cross-site scripting vulnerability

Metaphorcreations · Ditty

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Metaphor Creations Ditty plugin <= 3.0.32 versions.

5.4 CVSS 3.1 Medium EPSS 0.39% · top 69.8% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score
0.39%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Metaphor Creations Ditty plugin <= 3.0.32 versions.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-23874 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2025-8085Metaphorcreations ditty server-side request forgery (ssrf) vulnerabilityThe Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated v…EPSS 17%6.1CVE-2024-6715Metaphorcreations ditty vulnerabilityThe Ditty WordPress plugin before 3.1.46 re-introduced a previously fixed security issue (https://wpscan.com/vulnerability/80a9eb3a-2cb1-4844-9004-ba…EPSS 0.35%6.1CVE-2023-4148Metaphorcreations ditty cross-site scripting vulnerabilityThe Ditty WordPress plugin before 3.1.25 does not sanitise and escape some parameters and generated URLs before outputting them back in attributes, l…EPSS 0.85%6.1CVE-2022-0533Metaphorcreations ditty cross-site scripting vulnerabilityThe Ditty (formerly Ditty News Ticker) WordPress plugin before 3.0.15 is affected by a Reflected Cross-Site Scripting (XSS) vulnerability.EPSS 1.8%5.4CVE-2024-6710Metaphorcreations ditty cross-site scripting vulnerabilityThe Ditty WordPress plugin before 3.1.45 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to p…EPSS 0.35%5.4CVE-2024-3939Metaphorcreations ditty cross-site scripting vulnerabilityThe Ditty WordPress plugin before 3.1.36 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to p…EPSS 0.40%4.8CVE-2024-13357Metaphorcreations ditty cross-site scripting vulnerabilityThe Ditty WordPress plugin before 3.1.52 does not sanitise and escape some of its settings, which could allow high privilege users such as author to …EPSS 0.31%4.8CVE-2024-9600Metaphorcreations ditty cross-site scripting vulnerabilityThe Ditty WordPress plugin before 3.1.47 does not sanitise and escape some of its settings, which could allow high privilege users such as author to …EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2023-23874), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.