CVE-2025-8085
HIGH EXPLOITED NUCLEIMetaphorcreations Ditty < 3.1.58 - SSRF
Title source: ruleDescription
The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.
Exploits (1)
github
WORKING POC
4 stars
by halilkirazkaya · poc
https://github.com/halilkirazkaya/cve-poc-garage/tree/main/2025/CVE-2025-8085.md
Nuclei Templates (1)
Ditty < 3.1.58 - Server-Side Request Forgery
HIGHVERIFIEDby s4e-io
Shodan:
http.html:"/wp-content/plugins/ditty-news-ticker/"
FOFA:
body="/wp-content/plugins/ditty-news-ticker/"
Scores
CVSS v3
8.6
EPSS
0.1092
EPSS Percentile
93.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Details
VulnCheck KEV
2025-11-14
CWE
CWE-918
Status
published
Products (1)
metaphorcreations/ditty
< 3.1.58
Published
Sep 08, 2025
Tracked Since
Feb 18, 2026