Security Advisory

CVE-2022-1323

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-08-08 13:45:37
Last updated 2024-08-03 00:03:05
Assigner WPScan
State PUBLISHED

Description

The Discy WordPress theme before 5.0 lacks authorization checks then processing ajax requests to the discy_update_options action, allowing any logged in users (with privileges as low as Subscriber,) to change Theme options by sending a crafted POST request.