Extension WordPress
Vulnérabilités Ditty – Responsive News Tickers, Sliders, and Lists
Cette page rassemble les failles publiées pour Ditty – Responsive News Tickers, Sliders, and Lists, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Ditty – Responsive News Tickers, Sliders, and Lists
15 fiches
Ditty <= 3.1.65 – Missing Authorization to Unauthenticated Sensitive Information Disclosure via ditty_init AJAX Action
The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.65. This is due to the plugin not properly verifying that a user is…
*-3.1.65
3.1.66
21/05/2026
Ditty <= 3.1.58 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Ditty plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.58 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-3.1.58
3.1.59
26/09/2025
Ditty <= 3.1.57 – Unauthenticated Server-Side Request Forgery
The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.57. This makes it possible for unauthenticated attackers to make web requests to…
*-3.1.57
3.1.58
18/08/2025
Ditty <= 3.1.51 – Authenticated (Author+) Stored Cross-Site Scripting
The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.1.51 due to insufficient input sanitization and output escaping. This…
*-3.1.51
3.1.52
06/03/2025
Ditty <= 3.1.46 – Authenticated (Author+) Stored Cross-Site Scripting
The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.1.46 due to insufficient input sanitization and output escaping. This…
*-3.1.46
3.1.47
31/10/2024
Ditty 3.1.39 – 3.1.45 – Authenticated (Author+) Stored Cross-Site Scripting
The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Content Title' field in versions 3.1.39 to 3.1.45 due to insufficient input sanitization and output escaping. This makes…
3.1.39-3.1.45
3.1.46
02/08/2024
Ditty – Responsive News Tickers, Sliders, and Lists <= 3.1.44 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Tiny MCE block in all versions up to, and including, 3.1.44 due to insufficient input sanitization and…
*-3.1.44
3.1.45
15/07/2024
Ditty – Responsive News Tickers, Sliders, and Lists <= 3.1.42 – Authenticated (Author+) Stored Cross-Site Scripting
The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the main text field in versions up to and including 3.1.42 due to insufficient input sanitization and output escaping.…
*-3.1.42
3.1.43
22/06/2024
Ditty – Responsive News Tickers, Sliders, and Lists <= 3.1.38 – Authenticated (Contributor+) PHP Object Injection
The Ditty plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.1.38 via deserialization of untrusted input when adding a new ditty. This makes it possible for authenticated attackers, with contributor-level access and…
*-3.1.38
3.1.39
07/05/2024
Ditty <= 3.1.35 – Authenticated (Author+) Stored Cross-Site Scripting
The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the default new tab parameter in all versions up to, and including, 3.1.35 due to insufficient input sanitization and…
*-3.1.35
3.1.36
06/05/2024
Ditty – Responsive News Tickers, Sliders, and Lists <= 3.1.31 – Authenticated (Author+) Stored Cross-Site Scripting
The Ditty plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.1.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
*-3.1.31
3.1.32
16/04/2024
Ditty <= 3.1.24 – Missing Authorization via save_ditty_permissions_check
The Ditty plugin for WordPress is vulnerable to unauthorized editing of dittys due to a missing capability check on the save_ditty_permissions_check function in versions up to, and including, 3.1.24. This makes it possible for unauthenticated attackers to edit…
*-3.1.24
3.1.25
13/11/2023
Ditty <= 3.1.24 – Reflected Cross-Site Scripting
The Ditty plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via unescaped URLs in versions up to, and including, 3.1.24 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
[*, 3.1.25)
3.1.25
29/08/2023
Ditty <= 3.0.32 – Authenticated (Contributor+) Stored Cross-Scripting via Shortcode
The Ditty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 3.0.32 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…
*-3.0.32
3.0.33
20/02/2023
Ditty (formerly Ditty News Ticker) <= 3.0.14 – Reflected Cross-Site Scripting
The Ditty (formerly Ditty News Ticker) WordPress plugin before 3.0.15 is affected by a Reflected Cross-Site Scripting (XSS) vulnerability.
[*, 3.0.15)
3.0.15
09/02/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.