CVE-2022-43490

WordPress Stream Plugin <= 3.9.2 is vulnerable to Cross Site Request Forgery (CSRF)

Cross-Site Request Forgery (CSRF) vulnerability in XWP Stream plugin <= 3.9.2 versions.


We have discovered 2,439 live websites that are affected by CVE-2022-43490.

Run a Free Instant Scan




Affected Software

Product  Stream
Category Wordpress Plugins
Vulnerable Domains2,439 live websites (5.12% of Stream install base)
Vulnerable Versions
  • from 0 through 3.9.2
Vulnerable Versions Count28 versions ( 76% of all versions)


Common Weakness Enumeration

CWE-352 Cross-Site Request Forgery (CSRF)



Details

  • Published - May 25, 2023
  • Updated - Apr 28, 2026

Credits

  • Lucio Sá (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2022-43490
United States1,201 websites



GB166 websites
Australia139 websites
Canada116 websites
Russia103 websites
Germany93 websites
Italy87 websites
Netherlands52 websites
Spain40 websites
France32 websites

Website Distribution by TLD

Number of websites using CVE-2022-43490
.com1,222 websites
.org161 websites
.com.au121 websites
.co.uk103 websites
.ru83 websites
.it72 websites
.net60 websites
.de51 websites
.nl49 websites
.ca37 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2022-43490

Top websites that are affected by CVE-2022-43490. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com United States**,***
******.com Singapore**,***
*************.com United States**,***
************.com United States**,***
******.*****.com United States**,***
*************.net United States**,***
*********.com United States**,***
**********.com United States**,***
*********.com United States**,***
*****.com United States**,***
See full domain list

FAQ

CVE-2022-43490 is Cross-Site Request Forgery (CSRF) in Stream
A total of 2,439 websites have been identified as vulnerable to CVE-2022-43490, based on global website indexing conducted by WebTechSurvey.
The Stream is affected by the CVE-2022-43490 vulnerability.
Stream versions up to and including 3.9.2 are vulnerable to CVE-2022-43490.