CVE-2022-1421

MEDIUM

Discy < 5.2 - Cross-Site Request Forgery via AJAX Actions

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-1421. PoCs published by nb1b3k.

AI-analyzed exploit summary This PoC demonstrates a CSRF vulnerability in Discy WordPress theme versions prior to 5.2, allowing an attacker to update arbitrary plugin settings via a crafted HTML form. The exploit leverages the lack of CSRF checks in the `discy_update_options` AJAX action.

Description

The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in admin change arbitrary 's settings including payment methods via a CSRF attack

Exploits (1)

nomisec WORKING POC 7 stars
by nb1b3k · poc
https://github.com/nb1b3k/CVE-2022-1421

This PoC demonstrates a CSRF vulnerability in Discy WordPress theme versions prior to 5.2, allowing an attacker to update arbitrary plugin settings via a crafted HTML form. The exploit leverages the lack of CSRF checks in the `discy_update_options` AJAX action.

Classification
Working Poc 100%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: Discy WordPress Theme < 5.2
Auth required
Prerequisites: Victim must be logged in as an admin · Victim must visit the malicious HTML page
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://wpscan.com/vulnerability/a7a24e8e-9056-4967-bcad-b96cc0c5b249

Scores

CVSS v3 4.3
EPSS 0.0124
EPSS Percentile 66.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-352
Status published
Products (1)
2code/discy < 5.2
Published Jun 08, 2022
Tracked Since Feb 18, 2026