Severity
6.5MEDIUMNVD
EPSS
0.3%
top 45.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 8
Latest updateOct 21

Description

The Discy WordPress theme before 5.0 lacks authorization checks then processing ajax requests to the discy_update_options action, allowing any logged in users (with privileges as low as Subscriber,) to change Theme options by sending a crafted POST request.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

NVD2code/discy< 5.0

🔴Vulnerability Details

3
GHSA
GHSA-q53h-7g74-r646: The Discy WordPress theme before 52022-08-09
CVEList
Discy < 5.0 - Subscriber+ Broken Access Control to change settings2022-08-08
GHSA
Denial of Service in http-swagger2022-04-22

📋Vendor Advisories

1
Red Hat
kernel: HID: core: fix shift-out-of-bounds in hid_report_raw_event2024-10-21
CVE-2022-1323 — Missing Authorization in 2code Discy | cvebase