Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical0
High2
Medium1
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2025-02-17

CVE-2024-13879 - Stream Plugin

The Stream plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.2 due to insufficient validation on the webhook feature. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services.

PLUGIN Stream

CVE-2024-13879

MEDIUM CVSS 5.5 2025-02-17
Threat Entry Updated 2024-09-26

CVE-2024-7423 - Stream Plugin

The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.1. This is due to missing or incorrect nonce validation on the network_options_action() function. This makes it possible for unauthenticated attackers to update arbitrary options that can lead to DoS or privilege escalation via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Stream

CVE-2024-7423

HIGH CVSS 8.8 2024-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24772 - Stream Plugin

The Stream WordPress plugin before 3.8.2 does not sanitise and validate the order GET parameter from the Stream Records admin dashboard before using it in a SQL statement, leading to an SQL injection issue.

PLUGIN Stream

CVE-2021-24772

HIGH CVSS 8.8 2021-11-17
Scroll to top