Discy <= 5.1 - Cross-Site Request Forgery to Settings Update

2022-05-16 00:00
Bibek Neupane

Strategic Overview

Vulnerability Overview

The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in admin change arbitrary 's settings including payment methods via a CSRF attack

Technical Analysis

REMEDIATION: Update to version 5.2, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C