Executive brief
Ditty is a WordPress plugin used to create dynamic content displays like news tickers and feeds. A subscriber-level user can access and perform actions they should not be allowed to, potentially viewing or manipulating other users' data or restricted content.
Technical details
A broken access control vulnerability exists in Ditty WordPress plugin versions up to 3.1.67, allowing authenticated subscribers to bypass authorization checks and access functionality or data intended for higher-privilege users. The vulnerability does not require special network conditions but does require an attacker to have a valid subscriber account on the target WordPress site. An attacker can exploit this to view restricted pages or perform restricted actions, such as accessing other users' data. The vulnerability has been patched in version 3.1.69 and later.
Affected products
- Metaphor Creations Ditty <= 3.1.67
Timeline
- 2026-08-26: disclosed
- 2026-08-26: patched: Fixed in version 3.1.69