CVE-2026-93339
Last modified
CVE-2026-93339 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that allows authenticated users with Author-level privileges or higher to inject arbitrary HTML elements by supplying malicious wrapper attribute values in layout tags. The ditty_layout_render_tag_wrapper() function inserts caller-supplied wrapper attribute values directly as HTML element names without allowlist validation, bypassing wp_kses_post() sanitization because KSES runs at save time before layout tag attributes are resolved at render time, causing the payload to execute in the browser of any visitor viewing posts or pages embedding the affected Ditty item.. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that allows authenticated users with Author-level privileges or higher to inject arbitrary HTML elements by supplying malicious wrapper attribute values in layout tags. The ditty_layout_render_tag_wrapper() function inserts caller-supplied wrapper attribute values directly as HTML element names without allowlist validation, bypassing wp_kses_post() sanitization because KSES runs at save time before layout tag attributes are resolved at render time, causing the payload to execute in the browser of any visitor viewing posts or pages embedding the affected Ditty item.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Metaphor Creations | Ditty | < 3.1.70 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-93339?
How severe is CVE-2026-93339?
How do I fix CVE-2026-93339?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-93312A flaw has been found in Freedesktop Poppler 26.07.0. Impact…4.3
- CVE-2026-93313A vulnerability was found in Freedesktop Poppler 26.07.0. Th…6.3
- CVE-2026-93314A vulnerability was determined in Freedesktop Poppler 26.07.…6.3
- CVE-2026-93331A vulnerability was identified in GPAC 26.08-DEV. This vulne…7.3
- CVE-2026-93337NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contain…7.8
- CVE-2026-93338Grandstream GWN7660ELR before firmware version 1.0.27.6 cont…5.3
- CVE-2026-9334Cpanel::JSON::XS versions before 4.41 for Perl allow type co…7.3
- CVE-2026-93340Gladys Assistant before 5.1.0 contains a password reset link…6.8
- CVE-2026-93341MarketKing plugin for WordPress before 2.1.72 contains a mis…4.3
- CVE-2026-93342MarketKing plugin for WordPress before 2.1.72 contains a mis…5.4
- CVE-2026-93343MarketKing plugin for WordPress before 2.1.72 contains a mis…6.5
- CVE-2026-93344MarketKing plugin for WordPress before 2.1.72 contains a mis…6.5
Are you affected by CVE-2026-93339?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
