Unrated severityNVD Advisory· Published Jul 29, 2026· Updated Jul 29, 2026
Streamit <= 4.5.0 - Unauthenticated Remote Code Execution via Arbitrary Function Call
CVE-2026-13423
Description
The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which invokes an attacker-supplied PHP function with an attacker-supplied argument array, allowing unauthenticated attackers to call arbitrary functions (for example to create an administrator account), leading to privilege escalation and remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/f85c5da1-412f-4079-8c44-708bc78c2b9b/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.