Thème WordPress
Vulnérabilités Discy – Social Questions and Answers WordPress Theme
Cette page rassemble les failles publiées pour Discy – Social Questions and Answers WordPress Theme, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Discy – Social Questions and Answers WordPress Theme
4 fiches
WPQA – Builder forms Addon For WordPress (<= 5.9.2), Himer (<= 1.9.3) and Discy (<= 5.5.3) – Authenticated (Subscriber+) Insecure Direct Object Reference
The WPQA – Builder forms Addon For WordPress plugin is vulnerable to insecure direct object reference in versions up to, and including, 5.9.2 along with the Himer (
*-5.5.3
Non indiqué
13/12/2022
Discy – Social Questions and Answers WordPress Theme <= 4.9 – Missing Authorization
The "Discy – Social Questions and Answers WordPress Theme" theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the discy_update_options AJAX action in versions up to, and including, 4.9. This makes it…
*-4.9
5.0
12/07/2022
Discy <= 5.1 – Cross-Site Request Forgery to Settings Reset
The Discy WordPress theme before 5.2 does not check for CSRF tokens in the AJAX action discy_reset_options, allowing an attacker to trick an admin into resetting the site settings back to defaults.
[*, 5.2)
5.2
16/05/2022
Discy <= 5.1 – Cross-Site Request Forgery to Settings Update
The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in admin change arbitrary 's settings including payment methods via a CSRF attack
[*, 5.2)
5.2
16/05/2022
Thèmes également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.