CVE-2022-1421

MEDIUM

2code Discy < 5.2 - CSRF

Title source: rule
STIX 2.1

Description

The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in admin change arbitrary 's settings including payment methods via a CSRF attack

Exploits (1)

nomisec WORKING POC 7 stars
by nb1b3k · poc
https://github.com/nb1b3k/CVE-2022-1421

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://wpscan.com/vulnerability/a7a24e8e-9056-4967-bcad-b96cc0c5b249

Scores

CVSS v3 4.3
EPSS 0.0761
EPSS Percentile 91.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-352
Status published
Products (1)
2code/discy < 5.2
Published Jun 08, 2022
Tracked Since Feb 18, 2026