PT-2022-13797 · WordPress · Discy

Veshraj Ghimire

·

Published

2022-08-08

·

Updated

2023-07-04

·

CVE-2022-1323

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Discy WordPress theme versions prior to 5.0
Description The issue allows any logged-in users, with privileges as low as Subscriber, to change theme options by sending a crafted POST request to the "discy update options" action due to a lack of authorization checks. This can be exploited by sending a crafted POST request.
Recommendations For versions prior to 5.0, update to version 5.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the "discy update options" action to prevent unauthorized changes to theme options.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-1323

Affected Products

Discy