The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.1. This is due to missing or incorrect nonce validation on the network_options_action() function. This makes it possible for unauthenticated attackers to update arbitrary options that can lead to DoS or privilege escalation via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
We have discovered 4,453 live websites that are affected by CVE-2024-7423.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 4,453 live websites (9.34% of Stream install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 33 versions ( 89% of all versions) |
| 2,213 websites | |
| 317 websites | |
| 263 websites | |
| 176 websites | |
| 169 websites | |
| 167 websites | |
| 129 websites | |
| 122 websites | |
| 107 websites | |
| 98 websites |
| .com | 2,187 websites |
| .org | 312 websites |
| .com.au | 241 websites |
| .co.uk | 179 websites |
| .nl | 153 websites |
| .ru | 105 websites |
| .de | 99 websites |
| .it | 97 websites |
| .net | 92 websites |
| .ca | 84 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.com | **,*** | ||
| ******.com | **,*** | ||
| ***********.com | **,*** | ||
| *********.com | **,*** | ||
| ******.com | **,*** | ||
| ******.****.********.edu | **,*** | ||
| *************.com | **,*** | ||
| ************.com | **,*** | ||
| ******.*****.com | **,*** | ||
| ***********.com | **,*** |
FAQ