MEDIUM
Metaphor Creations
CVE published 2026-09-21
CVE-2026-93339
A stored cross-site scripting vulnerability exists in Metaphor Creations Ditty (ditty-news-ticker) before version 3.1.70. Authenticated users with Author-level privileges or higher can inject arbitrary HTML elements by supplying malicious wrapper attribute values in layout tags. The ditty_layout_render_tag_wrapper() function directly inserts caller-supplied wrapper attribute values as HTML element names w [truncated]