PoC Index

CVE-2022-1421

MEDIUM 4.3EPSS 1.3%

The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in admin change arbitrary 's settings including payment methods via a CSRF attack

CVSS v3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
1.29% chance of exploitation in the next 30 days, 68th percentile
Published
2022-06-06
Updated
2024-08-03

Proof-of-concept exploits (2)

References

Related