CVE-2025-8085
🟠 Łataj w tym tygodniu
Brak autoryzacji w wtyczce Ditty WordPress umożliwia nieautoryzowanym użytkownikom dostęp do dowolnych URLi.
CVSS
8.6
EPSS
18.2%
Exploit
poc
Vendor
metaphorcreations
Opis źródłowy (NVD)
The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.6 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 18.2% |
| Opublikowano (NVD) | 2025-09-08 06:15:34 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-30 23:10:00 UTC |
Referencje
- https://wpscan.com/vulnerability/f42c37bb-1ae0-49ab-bd81-7864dff0fcff/ ([email protected]) [Exploit, Third Party Advisory]