vulnerability

WordPress Theme: discy: CVE-2022-1421: Cross-Site Request Forgery (CSRF)

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
May 16, 2022
Added
Dec 8, 2025
Modified
Dec 8, 2025

Description

The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in admin change arbitrary 's settings including payment methods via a CSRF attack

Solution

discy-theme-cve-2022-1421
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.