Impact
The vulnerability allows a malicious contributor to inject arbitrary script code into pages rendered by the Ditty plugin. This enables an attacker to perform client‑side code execution on any visitor who views the affected content, potentially leading to phishing, cookie theft, or defacement, but no specific privileged escalation or other attacks are indicated in the CVE description.
Affected Systems
WordPress sites using the Ditty plugin by metaphorcreations with version 3.1.69 or earlier are affected. The vulnerability does not involve any other WordPress core components.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers would need the ability to add content through the plugin’s contributor interface, which is available to users with contributor or higher roles. The likely attack vector is an authenticated contributor submitting malicious input via the frontend contributor form.
OpenCVE Enrichment