Description
The Ditty WordPress plugin before 3.1.43 does not sanitise and escape some of its blocks' settings, which could allow high privilege users such as authors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 13 May 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Metaphorcreations
Metaphorcreations ditty |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:metaphorcreations:ditty:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Metaphorcreations
Metaphorcreations ditty |
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-01T21:18:06.451Z
Reserved: 2024-05-31T19:22:00.397Z
Link: CVE-2024-5575
Updated: 2024-08-01T21:18:06.451Z
Status : Analyzed
Published: 2024-07-13T06:15:05.070
Modified: 2025-05-13T16:10:37.080
Link: CVE-2024-5575
No data.
OpenCVE Enrichment
No data.
Weaknesses