cleantalk
Vulnerabilities and Security Researches

Ditty – Responsive News Tickers, Sliders, and Lists, CVE-2023-4148

CVE, Research URL

CVE-2023-4148

Published on
Sep 25, 2023
Research Description
The Ditty WordPress plugin before 3.1.25 does not sanitise and escape some parameters and generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Affected versions
max 3.1.25.
Status
vulnerable