The Ditty—News Ticker & Display Items plugin for WordPress (versions prior to 3.1.58) contains an unauthenticated server-side request forgery (SSRF) vulnerability in its displayItems endpoint. This flaw allows unauthenticated attackers to send arbitrary HTTP requests to internal or external URLs, due to missing authorization checks. A proof-of-concept demonstrating the misuse via crafted JSON in a POST request has been published on WPScan (see references). Confirmed findings are detailed in this post.
References:

