Description
The Sreamit theme for WordPress is vulnerable to arbitrary file downloads in all versions up to, and including, 4.0.1. This is due to insufficient file validation in the 'st_send_download_file' function. This makes it possible for authenticated attackers, with subscriber-level access and above, to download arbitrary files.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Any version
Timeline
| 2025-03-19: | Discovered |
| 2025-03-19: | Vendor Notified |
| 2025-04-04: | Disclosed |
Credits
István Márton
References
www.wordfence.com/...-ed2f-435a-806c-1fc43cac0f80?source=cve
themeforest.net/...-video-streaming-wordpress-theme/29772881
documentation.iqonic.design/...mit/change-log/streamit-v4-0/