CVE-2026-13423
Description
The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which invokes an attacker-supplied PHP function with an attacker-supplied argument array, allowing unauthenticated attackers to call arbitrary functions (for example to create an administrator account), leading to privilege escalation and remote code execution.
Metadata
Severity & Metrics
No CVSS data available.
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Unknown | Streamit | — | 0 ≤ 4.5.0 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | CWE-94 Improper Control of Generation of Code ('Code Injection') |