← Vulnerability feed

Vulnerability record · CVE-2025-8085 · published 8 September 2025

CVE-2025-8085: Metaphorcreations ditty server-side request forgery (ssrf) vulnerability

Metaphorcreations · Ditty

The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

8.6 CVSS 3.1 High EPSS 17% · top 3.0% CWE-918 · Server-side request forgery (SSRF)
8.6CVSS 3.1 base score
17%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-8085 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.1CVE-2024-6715Metaphorcreations ditty vulnerabilityThe Ditty WordPress plugin before 3.1.46 re-introduced a previously fixed security issue (https://wpscan.com/vulnerability/80a9eb3a-2cb1-4844-9004-ba…EPSS 0.35%6.1CVE-2023-4148Metaphorcreations ditty cross-site scripting vulnerabilityThe Ditty WordPress plugin before 3.1.25 does not sanitise and escape some parameters and generated URLs before outputting them back in attributes, l…EPSS 0.85%6.1CVE-2022-0533Metaphorcreations ditty cross-site scripting vulnerabilityThe Ditty (formerly Ditty News Ticker) WordPress plugin before 3.0.15 is affected by a Reflected Cross-Site Scripting (XSS) vulnerability.EPSS 1.8%5.4CVE-2024-6710Metaphorcreations ditty cross-site scripting vulnerabilityThe Ditty WordPress plugin before 3.1.45 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to p…EPSS 0.35%5.4CVE-2024-3939Metaphorcreations ditty cross-site scripting vulnerabilityThe Ditty WordPress plugin before 3.1.36 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to p…EPSS 0.40%5.4CVE-2023-23874Metaphorcreations ditty cross-site scripting vulnerabilityAuth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Metaphor Creations Ditty plugin <= 3.0.32 versions.EPSS 0.39%4.8CVE-2024-13357Metaphorcreations ditty cross-site scripting vulnerabilityThe Ditty WordPress plugin before 3.1.52 does not sanitise and escape some of its settings, which could allow high privilege users such as author to …EPSS 0.31%4.8CVE-2024-9600Metaphorcreations ditty cross-site scripting vulnerabilityThe Ditty WordPress plugin before 3.1.47 does not sanitise and escape some of its settings, which could allow high privilege users such as author to …EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2025-8085), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.