← Vulnerability feed

Vulnerability record · CVE-2024-6710 · published 5 August 2024

CVE-2024-6710: Metaphorcreations ditty cross-site scripting vulnerability

Metaphorcreations · Ditty

The Ditty WordPress plugin before 3.1.45 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

5.4 CVSS 3.1 Medium EPSS 0.35% · top 73.5% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score
0.35%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

The Ditty WordPress plugin before 3.1.45 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-6710 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2025-8085Metaphorcreations ditty server-side request forgery (ssrf) vulnerabilityThe Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated v…EPSS 17%6.1CVE-2024-6715Metaphorcreations ditty vulnerabilityThe Ditty WordPress plugin before 3.1.46 re-introduced a previously fixed security issue (https://wpscan.com/vulnerability/80a9eb3a-2cb1-4844-9004-ba…EPSS 0.35%6.1CVE-2023-4148Metaphorcreations ditty cross-site scripting vulnerabilityThe Ditty WordPress plugin before 3.1.25 does not sanitise and escape some parameters and generated URLs before outputting them back in attributes, l…EPSS 0.85%6.1CVE-2022-0533Metaphorcreations ditty cross-site scripting vulnerabilityThe Ditty (formerly Ditty News Ticker) WordPress plugin before 3.0.15 is affected by a Reflected Cross-Site Scripting (XSS) vulnerability.EPSS 1.8%5.4CVE-2024-3939Metaphorcreations ditty cross-site scripting vulnerabilityThe Ditty WordPress plugin before 3.1.36 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to p…EPSS 0.40%5.4CVE-2023-23874Metaphorcreations ditty cross-site scripting vulnerabilityAuth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Metaphor Creations Ditty plugin <= 3.0.32 versions.EPSS 0.39%4.8CVE-2024-13357Metaphorcreations ditty cross-site scripting vulnerabilityThe Ditty WordPress plugin before 3.1.52 does not sanitise and escape some of its settings, which could allow high privilege users such as author to …EPSS 0.31%4.8CVE-2024-9600Metaphorcreations ditty cross-site scripting vulnerabilityThe Ditty WordPress plugin before 3.1.47 does not sanitise and escape some of its settings, which could allow high privilege users such as author to …EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2024-6710), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.