← Vulnerability feed

Vulnerability record · CVE-2024-13357 · published 15 May 2025

CVE-2024-13357: Metaphorcreations ditty cross-site scripting vulnerability

Metaphorcreations · Ditty

The Ditty WordPress plugin before 3.1.52 does not sanitise and escape some of its settings, which could allow high privilege users such as author to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

4.8 CVSS 3.1 Medium EPSS 0.31% · top 78.4% CWE-79 · Cross-site scripting
4.8CVSS 3.1 base score
0.31%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Ditty WordPress plugin before 3.1.52 does not sanitise and escape some of its settings, which could allow high privilege users such as author to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-13357 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2025-8085Metaphorcreations ditty server-side request forgery (ssrf) vulnerabilityThe Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated v…EPSS 17%6.1CVE-2024-6715Metaphorcreations ditty vulnerabilityThe Ditty WordPress plugin before 3.1.46 re-introduced a previously fixed security issue (https://wpscan.com/vulnerability/80a9eb3a-2cb1-4844-9004-ba…EPSS 0.35%6.1CVE-2023-4148Metaphorcreations ditty cross-site scripting vulnerabilityThe Ditty WordPress plugin before 3.1.25 does not sanitise and escape some parameters and generated URLs before outputting them back in attributes, l…EPSS 0.85%6.1CVE-2022-0533Metaphorcreations ditty cross-site scripting vulnerabilityThe Ditty (formerly Ditty News Ticker) WordPress plugin before 3.0.15 is affected by a Reflected Cross-Site Scripting (XSS) vulnerability.EPSS 1.8%5.4CVE-2024-6710Metaphorcreations ditty cross-site scripting vulnerabilityThe Ditty WordPress plugin before 3.1.45 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to p…EPSS 0.35%5.4CVE-2024-3939Metaphorcreations ditty cross-site scripting vulnerabilityThe Ditty WordPress plugin before 3.1.36 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to p…EPSS 0.40%5.4CVE-2023-23874Metaphorcreations ditty cross-site scripting vulnerabilityAuth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Metaphor Creations Ditty plugin <= 3.0.32 versions.EPSS 0.39%4.8CVE-2024-9600Metaphorcreations ditty cross-site scripting vulnerabilityThe Ditty WordPress plugin before 3.1.47 does not sanitise and escape some of its settings, which could allow high privilege users such as author to …EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2024-13357), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.