2Code Discy vulnerabilities
3 known vulnerabilities affecting 2code/discy.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2022-1323MEDIUMCVSS 6.5fixed in 5.02022-08-08
CVE-2022-1323 [MEDIUM] CWE-862 CVE-2022-1323: The Discy WordPress theme before 5.0 lacks authorization checks then processing ajax requests to the
The Discy WordPress theme before 5.0 lacks authorization checks then processing ajax requests to the discy_update_options action, allowing any logged in users (with privileges as low as Subscriber,) to change Theme options by sending a crafted POST request.
nvd
CVE-2022-1422MEDIUMCVSS 6.5fixed in 5.22022-06-08
CVE-2022-1422 [MEDIUM] CWE-352 CVE-2022-1422: The Discy WordPress theme before 5.2 does not check for CSRF tokens in the AJAX action discy_reset_o
The Discy WordPress theme before 5.2 does not check for CSRF tokens in the AJAX action discy_reset_options, allowing an attacker to trick an admin into resetting the site settings back to defaults.
nvd
CVE-2022-1421MEDIUMCVSS 4.3fixed in 5.22022-06-08
CVE-2022-1421 [MEDIUM] CWE-352 CVE-2022-1421: The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to
The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in admin change arbitrary 's settings including payment methods via a CSRF attack
nvd