← WordPress Vulnerabilities
WordPress security by component

Discy

Discy is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Aug 08, 2022; the highest CVE/CNA score is 6.5.

Theme slug: discy

CVE-2022-1323: Discy: A security weakness

Discy is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedAug 08, 2022
Safe version guidanceSee mitigation notes
Safe version
Aug 08, 2022 CVE-2022-1323
Discy: A security weakness
Discy is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD6.5
Jun 08, 2022 CVE-2022-1422
Discy: Cross-site request forgery
Discy is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.5
NVD6.5
Jun 08, 2022 CVE-2022-1421
Discy: Cross-site request forgery
Discy is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3