VendorsXWPstreamall versions
Vulnerabilities

XWP Stream

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2021-24772
Stream < 3.8.2 - Admin+ SQL Injection
Published 2021-11-17 · Modified
8.8EPSS 0.016
CVE-2024-7423
Stream <= 4.0.1 - Cross-Site Request Forgery to Arbitrary Options Update
Published 2024-09-13 · Analyzed
8.8EPSS 0.003
CVE-2022-43490
WordPress Stream Plugin <= 3.9.2 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2023-05-25 · Modified
8.8EPSS 0.003
CVE-2022-4384
Stream < 3.9.2 - Subscriber+ Alert Creation
Published 2023-02-06 · Modified
6.5EPSS 0.009
CVE-2022-43450
WordPress Stream Plugin <= 3.9.2 is vulnerable to Insecure Direct Object References (IDOR)
Published 2023-12-19 · Modified
6.5EPSS 0.007