Input validation vulnerability in Ditty – Responsive News Tickers, Sliders, and Lists 3.1.35

The Ditty plugin for WordPress, which is used for creating news tickers, sliders, and lists, has a security vulnerability that allows attackers to insert harmful web scripts into the plugin’s default new tab feature. This can happen because the plugin does not properly clean and protect the input and output of the scripts. As a result, anyone can access these injected pages and potentially be harmed.

Detected in:

Ditty – Responsive News Tickers, Sliders, and Lists fixed vulnerable versions: >= * <= 3.1.35

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.