CVE-2025-8085

HIGH EXPLOITED NUCLEI

Metaphorcreations Ditty < 3.1.58 - SSRF

Title source: rule

Description

The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

Exploits (1)

github WORKING POC 4 stars
by halilkirazkaya · poc
https://github.com/halilkirazkaya/cve-poc-garage/tree/main/2025/CVE-2025-8085.md

Nuclei Templates (1)

Ditty < 3.1.58 - Server-Side Request Forgery
HIGHVERIFIEDby s4e-io
Shodan: http.html:"/wp-content/plugins/ditty-news-ticker/"
FOFA: body="/wp-content/plugins/ditty-news-ticker/"

Scores

CVSS v3 8.6
EPSS 0.1092
EPSS Percentile 93.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Details

VulnCheck KEV 2025-11-14
CWE
CWE-918
Status published
Products (1)
metaphorcreations/ditty < 3.1.58
Published Sep 08, 2025
Tracked Since Feb 18, 2026