plugin

Ditty News Ticker Vulnerabilities

29 known security issues reported for the Ditty News Ticker WordPress plugin. Most recent disclosed Jul 22, 2026.

3 high 13 medium

Running Ditty News Ticker on your site? Check whether your installed version is affected.

Scan your site free

Ditty – Responsive News Tickers, Sliders, and Lists <= 3.1.66 - Missing Authorization

medium

The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.1.66. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.1.66
Fixed in:
3.1.67
Disclosed:
Jul 22, 2026

CVE-2026-27355 on NVD →

Ditty <= 3.1.65 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via ditty_init AJAX Action

high

The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.65. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrie...

CVSS:
7.5
Affected:
up to 3.1.65
Fixed in:
3.1.66
Disclosed:
May 21, 2026

CVE-2026-9011 on NVD →

Ditty <= 3.1.58 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Ditty plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.58 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will...

CVSS:
6.4
Affected:
up to 3.1.58
Fixed in:
3.1.59
Disclosed:
Sep 26, 2025

CVE-2025-60105 on NVD →

Ditty <= 3.1.57 - Unauthenticated Server-Side Request Forgery

high

The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.57. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application which can be used...

CVSS:
7.2
Affected:
up to 3.1.57
Fixed in:
3.1.58
Disclosed:
Aug 18, 2025

CVE-2025-8085 on NVD →

Ditty – Responsive News Tickers, Sliders, and Lists [ditty-news-ticker] < 3.1.52

unknown

[en] The Ditty WordPress plugin before 3.1.52 does not sanitise and escape some of its settings, which could allow high privilege users such as author to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 3.1.52
Fixed in:
3.1.52
Disclosed:
May 15, 2025

CVE-2024-13357 on NVD →

Ditty <= 3.1.51 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.1.51 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level perm...

CVSS:
6.4
Affected:
up to 3.1.51
Fixed in:
3.1.52
Disclosed:
Mar 6, 2025

CVE-2024-13357 on NVD →

Ditty – Responsive News Tickers, Sliders, and Lists [ditty-news-ticker] < 3.1.25

unknown

[en] Missing Authorization vulnerability in Metaphor Creations Ditty allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ditty: from n/a through 3.1.24.

Affected:
up to 3.1.25
Fixed in:
3.1.25
Disclosed:
Dec 9, 2024

CVE-2023-47764 on NVD →

Ditty – Responsive News Tickers, Sliders, and Lists [ditty-news-ticker] < 3.1.47

unknown

[en] The Ditty WordPress plugin before 3.1.47 does not sanitise and escape some of its settings, which could allow high privilege users such as author to perform Stored Cross-Site Scripting attacks.

Affected:
up to 3.1.47
Fixed in:
3.1.47
Disclosed:
Nov 21, 2024

CVE-2024-9600 on NVD →

Ditty <= 3.1.46 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.1.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level perm...

CVSS:
6.4
Affected:
up to 3.1.46
Fixed in:
3.1.47
Disclosed:
Oct 31, 2024

CVE-2024-9600 on NVD →

Ditty – Responsive News Tickers, Sliders, and Lists [ditty-news-ticker] < 3.1.46

unknown

[en] The Ditty WordPress plugin before 3.1.46 re-introduced a previously fixed security issue (https://wpscan.com/vulnerability/80a9eb3a-2cb1-4844-9004-ba2554b2d46c/) in v3.1.39

Affected:
up to 3.1.46
Fixed in:
3.1.46
Disclosed:
Aug 23, 2024

CVE-2024-6715 on NVD →

Ditty – Responsive News Tickers, Sliders, and Lists [ditty-news-ticker] < 3.1.45

unknown

[en] The Ditty WordPress plugin before 3.1.45 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

Affected:
up to 3.1.45
Fixed in:
3.1.45
Disclosed:
Aug 5, 2024

CVE-2024-6710 on NVD →

Ditty 3.1.39 - 3.1.45 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Content Title' field in versions 3.1.39 to 3.1.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access an...

CVSS:
6.4
Affected:
3.1.39 – 3.1.45
Fixed in:
3.1.46
Disclosed:
Aug 2, 2024

CVE-2024-6715 on NVD →

Ditty – Responsive News Tickers, Sliders, and Lists <= 3.1.44 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Tiny MCE block in all versions up to, and including, 3.1.44 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authen...

CVSS:
6.4
Affected:
up to 3.1.44
Fixed in:
3.1.45
Disclosed:
Jul 15, 2024

CVE-2024-6710 on NVD →

Ditty – Responsive News Tickers, Sliders, and Lists [ditty-news-ticker] < 3.1.43

unknown

[en] The Ditty WordPress plugin before 3.1.43 does not sanitise and escape some of its blocks' settings, which could allow high privilege users such as authors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

Affected:
up to 3.1.43
Fixed in:
3.1.43
Disclosed:
Jul 13, 2024

CVE-2024-5575 on NVD →

Ditty – Responsive News Tickers, Sliders, and Lists <= 3.1.42 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the main text field in versions up to and including 3.1.42 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author access and...

CVSS:
6.4
Affected:
up to 3.1.42
Fixed in:
3.1.43
Disclosed:
Jun 22, 2024

CVE-2024-5575 on NVD →

Ditty – Responsive News Tickers, Sliders, and Lists [ditty-news-ticker] < 3.1.36

unknown

[en] The Ditty WordPress plugin before 3.1.36 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 3.1.36
Fixed in:
3.1.36
Disclosed:
May 27, 2024

CVE-2024-3939 on NVD →

Ditty – Responsive News Tickers, Sliders, and Lists [ditty-news-ticker] < 3.1.39

unknown

[en] The Ditty plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.1.38 via deserialization of untrusted input when adding a new ditty. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the...

Affected:
up to 3.1.39
Fixed in:
3.1.39
Disclosed:
May 9, 2024

CVE-2024-3954 on NVD →

Ditty – Responsive News Tickers, Sliders, and Lists <= 3.1.38 - Authenticated (Contributor+) PHP Object Injection

high

The Ditty plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.1.38 via deserialization of untrusted input when adding a new ditty. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vuln...

CVSS:
8.8
Affected:
up to 3.1.38
Fixed in:
3.1.39
Disclosed:
May 7, 2024

CVE-2024-3954 on NVD →

Ditty <= 3.1.35 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the default new tab parameter in all versions up to, and including, 3.1.35 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inj...

CVSS:
6.4
Affected:
up to 3.1.35
Fixed in:
3.1.36
Disclosed:
May 6, 2024

CVE-2024-3939 on NVD →

Ditty – Responsive News Tickers, Sliders, and Lists [ditty-news-ticker] < 3.1.32

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metaphor Creations Ditty allows Stored XSS.This issue affects Ditty: from n/a through 3.1.31.

Affected:
up to 3.1.32
Fixed in:
3.1.32
Disclosed:
Apr 18, 2024

CVE-2024-32569 on NVD →

Ditty – Responsive News Tickers, Sliders, and Lists <= 3.1.31 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Ditty plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.1.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web...

CVSS:
5.4
Affected:
up to 3.1.31
Fixed in:
3.1.32
Disclosed:
Apr 16, 2024

CVE-2024-32569 on NVD →

Ditty <= 3.1.24 - Missing Authorization via save_ditty_permissions_check

medium

The Ditty plugin for WordPress is vulnerable to unauthorized editing of dittys due to a missing capability check on the save_ditty_permissions_check function in versions up to, and including, 3.1.24. This makes it possible for unauthenticated attackers to edit dittys.

CVSS:
5.3
Affected:
up to 3.1.24
Fixed in:
3.1.25
Disclosed:
Nov 13, 2023

CVE-2023-47764 on NVD →

Ditty – Responsive News Tickers, Sliders, and Lists [ditty-news-ticker] < 3.1.25

unknown

[en] The Ditty WordPress plugin before 3.1.25 does not sanitise and escape some parameters and generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Affected:
up to 3.1.25
Fixed in:
3.1.25
Disclosed:
Sep 25, 2023

CVE-2023-4148 on NVD →

Ditty <= 3.1.24 - Reflected Cross-Site Scripting

medium

The Ditty plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via unescaped URLs in versions up to, and including, 3.1.24 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can su...

CVSS:
6.1
Affected:
up to 3.1.25
Fixed in:
3.1.25
Disclosed:
Aug 29, 2023

CVE-2023-4148 on NVD →

Ditty – Responsive News Tickers, Sliders, and Lists [ditty-news-ticker] < 3.0.33

unknown

[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Metaphor Creations Ditty plugin <= 3.0.32 versions.

Affected:
up to 3.0.33
Fixed in:
3.0.33
Disclosed:
May 3, 2023

CVE-2023-23874 on NVD →

Ditty <= 3.0.32 - Authenticated (Contributor+) Stored Cross-Scripting via Shortcode

medium

The Ditty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 3.0.32 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above p...

CVSS:
6.4
Affected:
up to 3.0.32
Fixed in:
3.0.33
Disclosed:
Feb 20, 2023

CVE-2023-23874 on NVD →

Ditty – Responsive News Tickers, Sliders, and Lists [ditty-news-ticker] < 3.0.15

unknown

[en] The Ditty (formerly Ditty News Ticker) WordPress plugin before 3.0.15 is affected by a Reflected Cross-Site Scripting (XSS) vulnerability.

Affected:
up to 3.0.15
Fixed in:
3.0.15
Disclosed:
Mar 7, 2022

CVE-2022-0533 on NVD →

Ditty (formerly Ditty News Ticker) <= 3.0.14 - Reflected Cross-Site Scripting

medium

The Ditty (formerly Ditty News Ticker) WordPress plugin before 3.0.15 is affected by a Reflected Cross-Site Scripting (XSS) vulnerability.

CVSS:
6.1
Affected:
up to 3.0.15
Fixed in:
3.0.15
Disclosed:
Feb 9, 2022

CVE-2022-0533 on NVD →

Ditty – Responsive News Tickers, Sliders, and Lists [ditty-news-ticker] <= 3.1.58 (unfixed)

unknown
Affected:
up to 3.1.58
Fix:
No patched version reported

CVE-2025-60105 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database