Description
The Social Streams plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.1. This is due to the plugin not properly validating a user's identity prior to updating their user meta information in the update_user_meta() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change their user type to that of an administrator.
Problem types
CWE-272 Least Privilege Violation
Product status
Any version
Timeline
| 2025-07-22: | Disclosed |
Credits
Thanh Nam Tran
References
www.wordfence.com/...-6f93-4ee8-8d59-9165ebcd4dd1?source=cve
plugins.trac.wordpress.org/...eams/trunk/src/php/JsonAPI.php