Extension WordPress
Vulnérabilités Stream
Cette page rassemble les failles publiées pour Stream, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Stream
7 fiches
Stream <= 4.0.2 – Authenticated (Admin+) Server-Side Request Forgery
The Stream plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.2 due to insufficient validation on the webhook feature. This makes it possible for authenticated attackers, with administrator-level access and…
*-4.0.2
4.1.0
14/02/2025
Stream <= 4.0.1 – Cross-Site Request Forgery to Arbitrary Options Update
The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.1. This is due to missing or incorrect nonce validation on the network_options_action() function. This makes it possible for unauthenticated…
*-4.0.1
4.0.2
12/09/2024
Stream <= 3.9.2 – Missing Authorization via load_alerts_settings
The Stream plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the load_alerts_settings function in versions up to, and including, 3.9.2. This makes it possible for authenticated attackers with subscriber-level…
[*, 3.9.3)
3.9.3
25/04/2023
Stream <= 3.9.2 – Cross-Site Request Forgery
The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.9.2. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated…
*-3.9.2
3.9.3
18/04/2023
Stream <= 3.9.1 – Missing Authorization to Sensitive Information Disclosure
The Stream plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'save_new_alert' and 'get_new_alert_triggers_notifications' functions in versions up to, and including, 3.9.1. This makes it possible for subscriber-level attackers to use…
*-3.9.1
3.9.2
16/01/2023
Stream <= 3.8.1 – Admin+ SQL Injection
The Stream WordPress plugin before 3.8.2 does not sanitise and validate the order GET parameter from the Stream Records admin dashboard before using it in a SQL statement, leading to an SQL injection issue.
*-3.8.1
3.8.2
18/10/2021
Stream <= 3.0.5 – Sensitive Data Exposure
The Stream plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.0.5. This can allow unauthenticated attackers to extract sensitive data including logged entries.
*-3.0.5
3.0.6
31/05/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.