← Back

Discy

discy

Vendor: 2code • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
12code
1Discy
Nov 21, 2024
Aug 8, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Discy WordPress theme before 5.0 lacks authorization checks then processing ajax requests to the discy_update_options action, allowing any logged in users (with privileges as low as Subscriber,) to change Theme opti...Show more
The Discy WordPress theme before 5.0 lacks authorization checks then processing ajax requests to the discy_update_options action, allowing any logged in users (with privileges as low as Subscriber,) to change Theme options by sending a crafted POST request.Show less
12code
1Discy
Nov 21, 2024
Jun 8, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Discy WordPress theme before 5.2 does not check for CSRF tokens in the AJAX action discy_reset_options, allowing an attacker to trick an admin into resetting the site settings back to defaults.
12code
1Discy
Nov 21, 2024
Jun 8, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in admin change arbitrary 's settings including payment methods via a CSRF attack