Stream <= 4.2.0 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via Heartbeat API
medium
The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to access all St...
- CVSS:
- 6.5
- Affected:
- up to 4.2.0
- Fixed in:
- 4.2.1
- Disclosed:
- Aug 6, 2026
CVE-2026-11907 on NVD →
Stream [stream] < 4.1.0
unknown
[en] The Stream plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.2 due to insufficient validation on the webhook feature. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations...
- Affected:
- up to 4.1.0
- Fixed in:
- 4.1.0
- Disclosed:
- Feb 17, 2025
CVE-2024-13879 on NVD →
Stream <= 4.0.2 - Authenticated (Admin+) Server-Side Request Forgery
medium
The Stream plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.2 due to insufficient validation on the webhook feature. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations origi...
- CVSS:
- 5.5
- Affected:
- up to 4.0.2
- Fixed in:
- 4.1.0
- Disclosed:
- Feb 14, 2025
CVE-2024-13879 on NVD →
Stream [stream] < 4.0.2
unknown
[en] The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.1. This is due to missing or incorrect nonce validation on the network_options_action() function. This makes it possible for unauthenticated attackers to update arbitrary options that can lead to D...
- Affected:
- up to 4.0.2
- Fixed in:
- 4.0.2
- Disclosed:
- Sep 13, 2024
CVE-2024-7423 on NVD →
Stream <= 4.0.1 - Cross-Site Request Forgery to Arbitrary Options Update
high
The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.1. This is due to missing or incorrect nonce validation on the network_options_action() function. This makes it possible for unauthenticated attackers to update arbitrary options that can lead to DoS or...
- CVSS:
- 8.8
- Affected:
- up to 4.0.1
- Fixed in:
- 4.0.2
- Disclosed:
- Sep 12, 2024
CVE-2024-7423 on NVD →
Stream [stream] < 3.9.3
unknown
[en] Authorization Bypass Through User-Controlled Key vulnerability in XWP Stream.This issue affects Stream: from n/a through 3.9.2.
- Affected:
- up to 3.9.3
- Fixed in:
- 3.9.3
- Disclosed:
- Dec 19, 2023
CVE-2022-43450 on NVD →
Stream [stream] < 3.9.3
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in XWP Stream plugin <= 3.9.2 versions.
- Affected:
- up to 3.9.3
- Fixed in:
- 3.9.3
- Disclosed:
- May 25, 2023
CVE-2022-43490 on NVD →
Stream <= 3.9.2 - Missing Authorization via load_alerts_settings
medium
The Stream plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the load_alerts_settings function in versions up to, and including, 3.9.2. This makes it possible for authenticated attackers with subscriber-level permissions or above to view arbitrary alerts.
- CVSS:
- 4.3
- Affected:
- up to 3.9.3
- Fixed in:
- 3.9.3
- Disclosed:
- Apr 25, 2023
CVE-2022-43450 on NVD →
Stream <= 3.9.2 - Cross-Site Request Forgery
medium
The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.9.2. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to invoke this function via a forged request granted they can trick a si...
- CVSS:
- 4.3
- Affected:
- up to 3.9.2
- Fixed in:
- 3.9.3
- Disclosed:
- Apr 18, 2023
CVE-2022-43490 on NVD →
Stream [stream] < 3.9.2
unknown
[en] The Stream WordPress plugin before 3.9.2 does not prevent users with little privileges on the site (like subscribers) from using its alert creation functionality, which may enable them to leak sensitive information.
- Affected:
- up to 3.9.2
- Fixed in:
- 3.9.2
- Disclosed:
- Feb 6, 2023
CVE-2022-4384 on NVD →
Stream <= 3.9.1 - Missing Authorization to Sensitive Information Disclosure
medium
The Stream plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'save_new_alert' and 'get_new_alert_triggers_notifications' functions in versions up to, and including, 3.9.1. This makes it possible for subscriber-level attackers to use the plugin's alert functionality and...
- CVSS:
- 4.3
- Affected:
- up to 3.9.1
- Fixed in:
- 3.9.2
- Disclosed:
- Jan 16, 2023
CVE-2022-4384 on NVD →
Stream [stream] < 3.8.2
unknown
[en] The Stream WordPress plugin before 3.8.2 does not sanitise and validate the order GET parameter from the Stream Records admin dashboard before using it in a SQL statement, leading to an SQL injection issue.
- Affected:
- up to 3.8.2
- Fixed in:
- 3.8.2
- Disclosed:
- Nov 17, 2021
CVE-2021-24772 on NVD →
Stream <= 3.8.1 - Admin+ SQL Injection
high
The Stream WordPress plugin before 3.8.2 does not sanitise and validate the order GET parameter from the Stream Records admin dashboard before using it in a SQL statement, leading to an SQL injection issue.
- CVSS:
- 7.2
- Affected:
- up to 3.8.1
- Fixed in:
- 3.8.2
- Disclosed:
- Oct 18, 2021
CVE-2021-24772 on NVD →
Stream <= 3.0.5 - Sensitive Data Exposure
high
The Stream plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.0.5. This can allow unauthenticated attackers to extract sensitive data including logged entries.
- CVSS:
- 7.5
- Affected:
- up to 3.0.5
- Fixed in:
- 3.0.6
- Disclosed:
- May 31, 2016
Stream [stream] < 3.0.6
unknown
The Stream plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.0.5. This can allow unauthenticated attackers to extract sensitive data including logged entries.
- Affected:
- up to 3.0.6
- Fixed in:
- 3.0.6
- Disclosed:
- May 31, 2016
Stream [stream] < 3.0.6
unknown
Because of this vulnerability, unauthenticated users can export CSV or JSON of recent events.
Update the plugin.
- Affected:
- up to 3.0.6
- Fixed in:
- 3.0.6
- Disclosed:
- May 31, 2016
Stream [stream] < 3.0.6
unknown
The Stream WordPress plugin allows unauthenticated users to export CSV or JSON of recent events. The code only checks to see if the proper GET variables are passed to a valid backend WordPress handler and will happily export logged entries.
Reported to maintainers on 5/25/2016 and new version released 5/30/2016
- Affected:
- up to 3.0.6
- Fixed in:
- 3.0.6
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database