VYPR

Stream

by Xwp

CVEs (3)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2022-43450Med0.284.30.00Dec 19, 2023Authorization Bypass Through User-Controlled Key vulnerability in XWP Stream.This issue affects Stream: from n/a through 3.9.2.
CVE-2024-74230.000.01Sep 13, 2024The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.1. This is due to missing or incorrect nonce validation on the network_options_action() function. This makes it possible for unauthenticated attackers to update arbitrary options that can lead to DoS or privilege escalation via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVE-2022-434900.000.00May 25, 2023Cross-Site Request Forgery (CSRF) vulnerability in XWP Stream plugin <= 3.9.2 versions.