Discy - Social Questions and Answers WordPress Theme <= 4.9 - Missing Authorization
2022-07-12 00:00
Veshraj GhimireStrategic Overview
StatusPatched in 5.0
Affected ThemeDiscy - Social Questions and Answers WordPress Theme
Affected Version
<= 4.9CVSS6.3Medium
CVE
CVE-2022-1323Vulnerability Overview
The "Discy - Social Questions and Answers WordPress Theme" theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the discy_update_options AJAX action in versions up to, and including, 4.9. This makes it possible for authenticated attackers with minimal permissions, such as subscribers, to modify the plugin's settings.
Technical Analysis
REMEDIATION: Update to version 5.0, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C