A critical security vulnerability CVE-2024-3939 was discovered in the WordPress plugin Ditty, which was downloaded by more than 40k users. This vulnerability exposes websites to the risk of attacks using stored cross-site scripting (XSS), which can potentially lead to account hijacking and violation of the integrity of the website. (if an attacker has previously hacked into an administrator or editor account, they can use the backdoor to restore access)
CVE-2024-3939 – Ditty – Stored XSS to JS backdoor creation – POC
![CVE-2024-3939 – Ditty – Stored XSS to JS backdoor creation – POC CVE-2024-3939 – Ditty – Stored XSS to JS backdoor creation – POC](https://research.cleantalk.org/wp-content/uploads/2023/10/New_1_not_safe-1.png)