Privilege Escalation Vulnerability in Streamit Theme for WordPress
CVE-2025-2526
8.8HIGH
What is CVE-2025-2526?
The Streamit theme for WordPress has a critical vulnerability that allows unauthorized users to escalate their privileges through account takeover. This issue arises from inadequate validation of user identity during profile updates, specifically within the 'st_Authentication_Controller::edit_profile' function. As a result, an unauthenticated attacker can manipulate other users' email addresses, including those of administrators, which can lead to unauthorized password resets and full account access.
Affected Version(s)
Streamit * <= 4.0.2