← WordPress Vulnerabilities
WordPress security by component

Streamit

Streamit is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Jul 29, 2026; the highest CVE/CNA score is 8.8.

Theme slug: streamit

CVE-2026-13423: Streamit exposes unauthenticated arbitrary PHP function calls

Streamit theme through 4.5.0 exposes an unauthenticated AJAX route without authorization or nonce verification. The route accepts both an attacker-selected PHP function and an attacker-controlled argument array, then invokes that callable. This permits an anonymous attacker to call available PHP or WordPress functions, including a function sequence that creates an Administrator account, and can lead to full site takeover and remote code execution. WPScan has withheld the proof of concept until remediation, so the exact AJAX action, request parameter names, handler function, and callable invocation mechanism are not currently disclosed. WPScan reports no known fixed release.

PublishedJul 29, 2026
Safe version guidanceSee mitigation notes
Safe version
Jul 29, 2026 CVE-2026-13423
Streamit exposes unauthenticated arbitrary PHP function calls
Streamit theme through 4.5.0 exposes an unauthenticated AJAX route without authorization or nonce verification. The route accepts both an attacker-selected PHP function and an attacker-controlled argument array, then invokes that callable. This permits an anonymous attacker to call available PHP or WordPress functions, including a function sequence that creates an Administrator account, and can lead to full site takeover and remote code execution. WPScan has withheld the proof of concept until remediation, so the exact AJAX action, request parameter names, handler function, and callable invocation mechanism are not currently disclosed. WPScan reports no known fixed release.
See mitigation notes
CVE0.0
NVDPending
Apr 08, 2025 CVE-2025-2526
Streamit: Privilege escalation or authentication bypass
Streamit is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVDPending
Apr 08, 2025 CVE-2025-2525
Streamit: Dangerous file upload
Streamit is affected by dangerous file upload. Exploitation requires an authenticated WordPress account. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE8.8
NVDPending