


Perceptive Security
SOC/SIEM Consultancy

The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which invokes an …
Published:
28 juli 2026 om 22:00:00
Alert date:
29 juli 2026 om 14:01:13
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Zero-Day Vulnerabilities
The Streamit WordPress theme through version 4.5.0 contains a critical security flaw in one of its unauthenticated AJAX routes. The route fails to perform any authorization or nonce verification, allowing unauthenticated attackers to invoke arbitrary PHP functions with attacker-supplied arguments. This can be exploited to create administrator accounts, leading to full privilege escalation. The vulnerability also enables remote code execution on affected WordPress installations. No authentication is required to exploit this vulnerability, making it particularly dangerous. The issue is tracked as CVE-2026-13423 and has been documented by both NVD and WPScan.
Technical details
Mitigation steps:
Affected products:
Streamit WordPress Theme 4.5.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-13423
https://wpscan.com/vulnerability/f85c5da1-412f-4079-8c44-708bc78c2b9b/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
