WPQA - Builder forms Addon For WordPress (<= 5.9.2), Himer (<= 1.9.3) and Discy (<= 5.5.3) - Authenticated (Subscriber+) Insecure Direct Object Reference
medium
The WPQA - Builder forms Addon For WordPress plugin is vulnerable to insecure direct object reference in versions up to, and including, 5.9.2 along with the Himer (<= 1.9.3) and Discy (<= 5.5.3) WordPress themes. This is due to insufficient validation of user follows on the wpqa_following_you_ajax action. This makes it...
- CVSS:
- 4.3
- Affected:
- up to 5.5.3
- Fix:
- No patched version reported
- Disclosed:
- Dec 13, 2022
CVE-2022-3343 on NVD →
Discy [discy] < 5.0
unknown
[en] The Discy WordPress theme before 5.0 lacks authorization checks then processing ajax requests to the discy_update_options action, allowing any logged in users (with privileges as low as Subscriber,) to change Theme options by sending a crafted POST request.
- Affected:
- up to 5.0
- Fixed in:
- 5.0
- Disclosed:
- Aug 8, 2022
CVE-2022-1323 on NVD →
Discy - Social Questions and Answers WordPress Theme <= 4.9 - Missing Authorization
medium
The "Discy - Social Questions and Answers WordPress Theme" theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the discy_update_options AJAX action in versions up to, and including, 4.9. This makes it possible for authenticated attackers with minimal permissions, such as subsc...
- CVSS:
- 6.3
- Affected:
- up to 4.9
- Fixed in:
- 5.0
- Disclosed:
- Jul 12, 2022
CVE-2022-1323 on NVD →
Discy [discy] < 5.2
unknown
[en] The Discy WordPress theme before 5.2 does not check for CSRF tokens in the AJAX action discy_reset_options, allowing an attacker to trick an admin into resetting the site settings back to defaults.
- Affected:
- up to 5.2
- Fixed in:
- 5.2
- Disclosed:
- Jun 6, 2022
CVE-2022-1422 on NVD →
Discy [discy] < 5.2
unknown
[en] The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in admin change arbitrary 's settings including payment methods via a CSRF attack
- Affected:
- up to 5.2
- Fixed in:
- 5.2
- Disclosed:
- Jun 6, 2022
CVE-2022-1421 on NVD →
Discy <= 5.1 - Cross-Site Request Forgery to Settings Update
high
The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in admin change arbitrary 's settings including payment methods via a CSRF attack
- CVSS:
- 8.8
- Affected:
- up to 5.2
- Fixed in:
- 5.2
- Disclosed:
- May 16, 2022
CVE-2022-1421 on NVD →
Discy <= 5.1 - Cross-Site Request Forgery to Settings Reset
high
The Discy WordPress theme before 5.2 does not check for CSRF tokens in the AJAX action discy_reset_options, allowing an attacker to trick an admin into resetting the site settings back to defaults.
- CVSS:
- 8.8
- Affected:
- up to 5.2
- Fixed in:
- 5.2
- Disclosed:
- May 16, 2022
CVE-2022-1422 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database