CVE-2024-5575: Ditty < 3.1.43 - Author+ Stored XSS
The Ditty WordPress plugin before 3.1.43 does not sanitise and escape some of its blocks' settings, which could allow high privilege users such as authors to perform Cross-Site Scripting attacks even when unfilteredhtml is disallowed
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5575?
CVE-2024-5575 has been classified as a high severity vulnerability due to its potential for Cross-Site Scripting attacks.
How do I fix CVE-2024-5575?
To address CVE-2024-5575, update the Ditty WordPress plugin to version 3.1.43 or later.
Who is affected by CVE-2024-5575?
CVE-2024-5575 affects users of the Ditty WordPress plugin before version 3.1.43, particularly those with high privilege roles such as authors.
What type of vulnerability is CVE-2024-5575?
CVE-2024-5575 is a Cross-Site Scripting (XSS) vulnerability due to improper sanitization and escaping of block settings.
Can unfiltered_html be disabled in the context of CVE-2024-5575?
Yes, CVE-2024-5575 can still allow XSS attacks even when the unfiltered_html capability is disabled for high privilege users.