Discy <= 5.1 - Cross-Site Request Forgery to Settings Update
2022-05-16 00:00
Bibek NeupaneStrategic Overview
StatusPatched in 5.2
Affected ThemeDiscy - Social Questions and Answers WordPress Theme
Affected Version
< 5.2CVSS8.8High
CVE
CVE-2022-1421Vulnerability Overview
The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in admin change arbitrary 's settings including payment methods via a CSRF attack
Technical Analysis
REMEDIATION: Update to version 5.2, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C