CVE-2026-13423
CRITICALStreamit <= 4.5.0 - Unauthenticated Remote Code Execution via Arbitrary Function Call
Title source: cnaDescription
The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which invokes an attacker-supplied PHP function with an attacker-supplied argument array, allowing unauthenticated attackers to call arbitrary functions (for example to create an administrator account), leading to privilege escalation and remote code execution.
References (1)
Core 1
Core References
Exploit exploit
vdb-entry
technical-description
https://wpscan.com/vulnerability/f85c5da1-412f-4079-8c44-708bc78c2b9b/
Scores
CVSS v3
9.8
EPSS
0.0054
EPSS Percentile
42.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-94
Status
published
Products (1)
None/Streamit
< 4.5.0
Published
Jul 29, 2026
Tracked Since
Jul 29, 2026