What is CVE-2026-13423?
The Streamit WordPress theme through version 4.5.0 lacks authorization and nonce verification on an unauthenticated AJAX route, allowing unauthenticated attackers to invoke arbitrary PHP functions with supplied arguments. This vulnerability could lead to remote code execution (RCE), requiring immediate theme update or deactivation.
Azərbaycanca: Streamit WordPress temasının 4.5.0-ə qədər versiyalarında, autentifikasiya olunmamış AJAX route üzərində avtorizasiya və nonce yoxlanışının olmaması səbəbilə autentifikasiya olunmamış hücumçular təhlükəli PHP funksiyalarını çağıra bilər. Bu boşluq təsirlənmiş saytlarda uzaqdan kod icrasına (RCE) səbəb ola bilər, ona görə də dərhal tema yenilənməli və ya dayandırılmalıdır.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which versions of the Streamit WordPress theme are affected by CVE-2026-13423?
The Streamit theme through version 4.5.0 is affected by this vulnerability.
What can an attacker achieve by exploiting CVE-2026-13423?
An unauthenticated attacker can invoke arbitrary PHP functions, potentially leading to remote code execution (RCE) on the affected site.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.