theme

Discy Vulnerabilities

7 known security issues reported for the Discy WordPress theme. Most recent disclosed Dec 13, 2022.

2 high 2 medium

Running Discy on your site? Check whether your installed version is affected.

Scan your site free

WPQA - Builder forms Addon For WordPress (<= 5.9.2), Himer (<= 1.9.3) and Discy (<= 5.5.3) - Authenticated (Subscriber+) Insecure Direct Object Reference

medium

The WPQA - Builder forms Addon For WordPress plugin is vulnerable to insecure direct object reference in versions up to, and including, 5.9.2 along with the Himer (<= 1.9.3) and Discy (<= 5.5.3) WordPress themes. This is due to insufficient validation of user follows on the wpqa_following_you_ajax action. This makes it...

CVSS:
4.3
Affected:
up to 5.5.3
Fix:
No patched version reported
Disclosed:
Dec 13, 2022

CVE-2022-3343 on NVD →

Discy [discy] < 5.0

unknown

[en] The Discy WordPress theme before 5.0 lacks authorization checks then processing ajax requests to the discy_update_options action, allowing any logged in users (with privileges as low as Subscriber,) to change Theme options by sending a crafted POST request.

Affected:
up to 5.0
Fixed in:
5.0
Disclosed:
Aug 8, 2022

CVE-2022-1323 on NVD →

Discy - Social Questions and Answers WordPress Theme <= 4.9 - Missing Authorization

medium

The "Discy - Social Questions and Answers WordPress Theme" theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the discy_update_options AJAX action in versions up to, and including, 4.9. This makes it possible for authenticated attackers with minimal permissions, such as subsc...

CVSS:
6.3
Affected:
up to 4.9
Fixed in:
5.0
Disclosed:
Jul 12, 2022

CVE-2022-1323 on NVD →

Discy [discy] < 5.2

unknown

[en] The Discy WordPress theme before 5.2 does not check for CSRF tokens in the AJAX action discy_reset_options, allowing an attacker to trick an admin into resetting the site settings back to defaults.

Affected:
up to 5.2
Fixed in:
5.2
Disclosed:
Jun 6, 2022

CVE-2022-1422 on NVD →

Discy [discy] < 5.2

unknown

[en] The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in admin change arbitrary 's settings including payment methods via a CSRF attack

Affected:
up to 5.2
Fixed in:
5.2
Disclosed:
Jun 6, 2022

CVE-2022-1421 on NVD →

Discy <= 5.1 - Cross-Site Request Forgery to Settings Update

high

The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in admin change arbitrary 's settings including payment methods via a CSRF attack

CVSS:
8.8
Affected:
up to 5.2
Fixed in:
5.2
Disclosed:
May 16, 2022

CVE-2022-1421 on NVD →

Discy <= 5.1 - Cross-Site Request Forgery to Settings Reset

high

The Discy WordPress theme before 5.2 does not check for CSRF tokens in the AJAX action discy_reset_options, allowing an attacker to trick an admin into resetting the site settings back to defaults.

CVSS:
8.8
Affected:
up to 5.2
Fixed in:
5.2
Disclosed:
May 16, 2022

CVE-2022-1422 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database