The Discy WordPress theme before 5.0 lacks authorization...
Moderate severity
Unreviewed
Published
Aug 9, 2022
to the GitHub Advisory Database
•
Updated Jun 27, 2023
Description
Published by the National Vulnerability Database
Aug 8, 2022
Published to the GitHub Advisory Database
Aug 9, 2022
Last updated
Jun 27, 2023
The Discy WordPress theme before 5.0 lacks authorization checks then processing ajax requests to the discy_update_options action, allowing any logged in users (with privileges as low as Subscriber,) to change Theme options by sending a crafted POST request.
References