The plugin lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs. v3.1.57 attempted to fix the issue with a nonce check, however any authenticated users, such as subscriber can retrieve it.
id: CVE-2025-8085
info:
name: Ditty < 3.1.58 - Server-Side Request Forgery
author: s4e-io
sev
...