WordPress security by component
WpStream
Plugin description
WpStream is a WordPress component with 6 published CVE records in this archive. The latest tracked vulnerability was published Jun 15, 2026; the highest CVE/CNA score is 5.4.
Plugin slug:
wpstreamLatest vulnerability
CVE-2026-39527: WpStream: Dangerous file upload
WpStream is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is n/a to < 4.11.2.
| Safe version |
|
||
|---|---|---|---|
| Jun 15, 2026 |
CVE-2026-39527
WpStream: Dangerous file upload
WpStream is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is n/a to < 4.11.2.
|
4.11.2 |
CVE5.4
NVDPending
|
| Apr 08, 2026 |
CVE-2026-39526
WpStream: A security weakness
WpStream is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 4.11.2.
|
4.11.2 |
CVE5.4
NVDPending
|
| Dec 24, 2025 |
CVE-2025-68522
WpStream: A security weakness
WpStream is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Dec 24, 2025 |
CVE-2025-68521
WpStream: A security weakness
WpStream is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Nov 22, 2023 |
CVE-2023-27458
Wpstream: Cross-site request forgery
Wpstream is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Jul 27, 2023 |
CVE-2023-38512
WpStream: Cross-site request forgery
WpStream is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|