Streamit
Streamit is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Jul 29, 2026; the highest CVE/CNA score is 8.8.
streamitCVE-2026-13423: Streamit exposes unauthenticated arbitrary PHP function calls
Streamit theme through 4.5.0 exposes an unauthenticated AJAX route without authorization or nonce verification. The route accepts both an attacker-selected PHP function and an attacker-controlled argument array, then invokes that callable. This permits an anonymous attacker to call available PHP or WordPress functions, including a function sequence that creates an Administrator account, and can lead to full site takeover and remote code execution. WPScan has withheld the proof of concept until remediation, so the exact AJAX action, request parameter names, handler function, and callable invocation mechanism are not currently disclosed. WPScan reports no known fixed release.
| Safe version |
|
||
|---|---|---|---|
| Jul 29, 2026 |
CVE-2026-13423
Streamit exposes unauthenticated arbitrary PHP function calls
Streamit theme through 4.5.0 exposes an unauthenticated AJAX route without authorization or nonce verification. The route accepts both an attacker-selected PHP function and an attacker-controlled argument array, then invokes that callable. This permits an anonymous attacker to call available PHP or WordPress functions, including a function sequence that creates an Administrator account, and can lead to full site takeover and remote code execution. WPScan has withheld the proof of concept until remediation, so the exact AJAX action, request parameter names, handler function, and callable invocation mechanism are not currently disclosed. WPScan reports no known fixed release.
|
See mitigation notes |
CVE0.0
NVDPending
|
| Apr 08, 2025 |
CVE-2025-2526
Streamit: Privilege escalation or authentication bypass
Streamit is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Apr 08, 2025 |
CVE-2025-2525
Streamit: Dangerous file upload
Streamit is affected by dangerous file upload. Exploitation requires an authenticated WordPress account. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
|
See mitigation notes |
CVE8.8
NVDPending
|