PT-2026-65691 · WordPress · Streamit
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Streamit WordPress theme versions prior to 4.5.1
Description
An unauthenticated AJAX route fails to perform authorization or nonce verification. This allows unauthenticated attackers to invoke arbitrary PHP functions by providing a function name and an argument array, which can lead to privilege escalation, such as the creation of an administrator account, and remote code execution.
Recommendations
Update the Streamit WordPress theme to version 4.5.1 or later.
Exploit
Fix
LPE
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Streamit