Unauthenticated Broken Access Control in Ditty Plugin by WordPress
CVE-2026-27355
5.3MEDIUM
What is CVE-2026-27355?
The Ditty Plugin for WordPress is affected by an unauthenticated broken access control vulnerability, which allows unauthorized users to gain access to features that should be restricted. This serious flaw could permit malicious actors to exploit certain functionalities of the plugin, thus compromising the security of WordPress installations utilizing affected versions. It is imperative for users to update their Ditty Plugin to the latest version to mitigate risks associated with this vulnerability.
Affected Version(s)
Ditty <= 3.1.66