Executive brief
Ditty is a popular WordPress plugin used to create and display dynamic news tickers and content sliders on websites. A security flaw in versions up to 3.1.66 allows unauthenticated visitors to perform actions that should be restricted to administrators. While the impact is currently rated as low, it could potentially allow unauthorized changes to how content is displayed or cause minor service disruptions.
Technical details
A broken access control vulnerability exists in the Ditty plugin (formerly Ditty News Ticker) for WordPress due to missing authorization checks (CWE-862). The flaw allows an unauthenticated remote attacker to execute functions that lack proper permission or nonce validation. According to the CVSS vector, the primary impact is on availability (Low), suggesting the vulnerability may allow unauthorized modification or deletion of ticker settings or content. As of the advisory date, no official patch has been released.
Affected products
- Metaphor Creations, LLC Ditty (formerly Ditty News Ticker) <= 3.1.66
Timeline
- 2025-11-26: other: Reported by researcher Legion Hunter
- 2026-07-22: advisory: Advisory published by Patchstack
- 2026-07-23: disclosed: CVE published to NVD