The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which invokes an attacker-supplied PHP function with an attacker-supplied argument array, allowing unauthenticated attackers to call arbitrary functions (for example to create an administrator account), leading to privilege escalation and remote code execution.
CVE-2026-13423
NONE
Updated Jul 29, 2026
WordPress
CVE Details
CVE ID
CVE-2026-13423
Published Date
Jul 29, 2026
Vendor
WordPress
Severity
NONE
Impact
Minimal impact
Source
View Advisory