Vulnerability detail
Enriched intelligence for a single CVE
High
CVE-2025-8085
PUBLISHEDDitty < 3.1.58 - Unauthenticated SSRF
- Vendor
- Unknown
- Product
- Ditty
- Published
- Sep 08, 2025
- EPSS
- 10.9% · 94% pctl
Automate this intelligence with the Pro API
Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot data — is available programmatically for VM, SOC, and CTI workflows.
Description
The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.
Weaknesses (CWE)
-
Server-Side Request Forgery (SSRF)
CVSS scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Exploitation status
Exploited in the wild
Recorded 2026-06-08 00:00:00 UTC · The Shadowserver (via CIRCL)
Known exploited vulnerability sources
Catalogues that list this CVE as a known exploited vulnerability.
| Source | Added |
|---|---|
| The Shadowserver (via CIRCL) First | 2026-06-08 00:00 UTC |
Scanner integrations
| Scanner | Reference | Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-8085.yaml | Jun 01, 2026 |
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Detected by Nuclei
-
Added to KEVIntel