Ditty Plugin Vulnerability Could Lead to Cross-Site Scripting Attacks
CVE-2024-5575
Currently unrated 🤨
Summary
The Ditty WordPress plugin before 3.1.43 does not sanitise and escape some of its blocks' settings, which could allow high privilege users such as authors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
Affected Version(s)
Ditty < 3.1.43
Timeline
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database
Credit
Dmitrii Ignatyev
WPScan