Broken Access Control in Ditty Plugin by WordPress
CVE-2026-81274
5.3MEDIUM
What is CVE-2026-81274?
The Ditty plugin for WordPress, versions 3.1.67 and earlier, exhibits a broken access control vulnerability that can potentially allow unauthorized users to access restricted functionalities. This flaw may lead to unintended exposure of sensitive information or modification of restricted resources. Site administrators are encouraged to review their implementations and apply appropriate security measures to mitigate risks associated with this vulnerability.
Affected Version(s)
Ditty <= 3.1.67