documentation.iqonic.design
https://documentation.iqonic.design/streamit/change-log/streamit-v4-0 CVE-2025-2525
HIGH
Streamit <= 4.0.1 - Authenticated (Subscriber+) Arbitrary File Upload
Record summary
CVE-2025-2525 has a selected CVSS score of 8.8 (high).
Description
The Streamit theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'st_Authentication_Controller::edit_profile' function in all versions up to, and including, 4.0.1. This makes it possible for authenticated attackers, with subscriber-level and above permissions, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 8, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
StreamitBrowse iqonicdesign / StreamitDefault status: unaffected | CVE List | Through 4.0.1 | affected |
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-2525 themeforest.net
https://themeforest.net/item/streamit-video-streaming-wordpress-theme/29772881 wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/83a58119-d0ed-47fe-93d1-1aa1def2cf44?source=cve