Input validation vulnerability in Ditty – Responsive News Tickers, Sliders, and Lists 3.1.57

The Ditty plugin for WordPress, which is used for displaying news tickers, sliders, and lists, has a vulnerability called Server-Side Request Forgery. This means that anyone, even those who are not logged in, can make requests to other websites through the plugin. This can be used to access and change information from internal services.

Detected in:

Ditty – Responsive News Tickers, Sliders, and Lists fixed vulnerable versions: >= * <= 3.1.57

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.