CVE-2024-7423

Stream <= 4.0.1 - Cross-Site Request Forgery to Arbitrary Options Update

The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.1. This is due to missing or incorrect nonce validation on the network_options_action() function. This makes it possible for unauthenticated attackers to update arbitrary options that can lead to DoS or privilege escalation via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.


We have discovered 4,453 live websites that are affected by CVE-2024-7423.

Run a Free Instant Scan




Affected Software

Product  Stream
Category Wordpress Plugins
Vulnerable Domains4,453 live websites (9.34% of Stream install base)
Vulnerable Versions
  • from 0 through 4.0.1
Vulnerable Versions Count33 versions ( 89% of all versions)


Common Weakness Enumeration

CWE-352 Cross-Site Request Forgery (CSRF)



Details

  • Published - Sep 13, 2024
  • Updated - Apr 8, 2026

Credits

  • vgo0 (finder)

Website Distribution by Country

Number of websites using CVE-2024-7423
United States2,213 websites



Australia317 websites
GB263 websites
Germany176 websites
Netherlands169 websites
Canada167 websites
Russia129 websites
Italy122 websites
Spain107 websites
Singapore98 websites

Website Distribution by TLD

Number of websites using CVE-2024-7423
.com2,187 websites
.org312 websites
.com.au241 websites
.co.uk179 websites
.nl153 websites
.ru105 websites
.de99 websites
.it97 websites
.net92 websites
.ca84 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-7423

Top websites that are affected by CVE-2024-7423. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States**,***
******.com United States**,***
***********.com United States**,***
*********.com United States**,***
******.com Singapore**,***
******.****.********.edu United States**,***
*************.com United States**,***
************.com United States**,***
******.*****.com United States**,***
***********.com United States**,***
See full domain list

FAQ

CVE-2024-7423 is Cross-Site Request Forgery (CSRF) in Stream
A total of 4,453 websites have been identified as vulnerable to CVE-2024-7423, based on global website indexing conducted by WebTechSurvey.
The Stream is affected by the CVE-2024-7423 vulnerability.
Stream versions up to and including 4.0.1 are vulnerable to CVE-2024-7423.