Vulnerability Description
The Discy WordPress theme before 5.0 lacks authorization checks then processing ajax requests to the discy_update_options action, allowing any logged in users (with privileges as low as Subscriber,) to change Theme options by sending a crafted POST request.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| 2Code | Discy | < 5.0 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/2d8020e1-6489-4555-9956-2dc190aaa61bExploitThird Party Advisory
- https://wpscan.com/vulnerability/2d8020e1-6489-4555-9956-2dc190aaa61bExploitThird Party Advisory
FAQ
What is CVE-2022-1323?
CVE-2022-1323 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The Discy WordPress theme before 5.0 lacks authorization checks then processing ajax requests to the discy_update_options action, allowing any logged in users (with privileges as low as Subscriber,) ...
How severe is CVE-2022-1323?
CVE-2022-1323 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-1323?
Check the references section above for vendor advisories and patch information. Affected products include: 2Code Discy.