documentation.iqonic.design
https://documentation.iqonic.design/streamit/change-log/streamit-v4-0 CVE-2025-2519
MEDIUM
Streamit <= 4.0.1 - Authenticated (Subscriber+) Arbitrary File Download
Record summary
CVE-2025-2519 has a selected CVSS score of 6.5 (medium).
Description
The Sreamit theme for WordPress is vulnerable to arbitrary file downloads in all versions up to, and including, 4.0.1. This is due to insufficient file validation in the 'st_send_download_file' function. This makes it possible for authenticated attackers, with subscriber-level access and above, to download arbitrary files.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 8, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
StreamitBrowse iqonicdesign / StreamitDefault status: unaffected | CVE List | Through 4.0.1 | affected |
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-2519 themeforest.net
https://themeforest.net/item/streamit-video-streaming-wordpress-theme/29772881 wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/fd28c405-ed2f-435a-806c-1fc43cac0f80?source=cve