CVE-2025-60105: WordPress Ditty Plugin <= 3.1.58 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in metaphorcreations Ditty allows Stored XSS. This issue affects Ditty: from n/a through 3.1.58.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in metaphorcreations Ditty ditty-news-ticker allows Stored XSS.This issue affects Ditty: from n/a through <= 3.1.58.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60105?
CVE-2025-60105 is classified as a Critical severity vulnerability due to its potential for stored Cross-site Scripting (XSS).
How do I fix CVE-2025-60105?
To fix CVE-2025-60105, upgrade the Metaphor Creations Ditty plugin to version 3.1.59 or later where the vulnerability is patched.
What versions of Ditty are affected by CVE-2025-60105?
CVE-2025-60105 affects versions of Ditty from the initial release up to 3.1.58.
Can CVE-2025-60105 lead to data breaches?
Yes, CVE-2025-60105 can lead to data breaches as it allows attackers to inject malicious scripts into web pages that can steal user information.
How can I identify if I'm vulnerable to CVE-2025-60105?
You can identify if you're vulnerable to CVE-2025-60105 by checking if your Ditty plugin version is 3.1.58 or lower.