Stream

Stream is a plugin for WordPress that allows users to monitor and track user activity on their website, including login attempts, plugin activations, and post deletions. The plugin records user and system actions in an activity stream, which can be filtered by user, role, context, action, or IP address. Stream also offers email alerts and integrations with third-party services like Slack and IFTTT. The plugin supports a network view of all activity records on a Multisite and the ability to set exclude rules to ignore certain kinds of user activity. Built-in tracking integrations are available for popular plugins and core actions.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in Stream 4.0.2

    Fixed

    The Stream plugin for WordPress has a security issue that allows attackers to send fake requests from the plugin to other websites. This can be done by someone who has high-level access to the plugin...

    Read More
  • Input validation vulnerability in Stream 4.0.1

    Fixed

    The Stream plugin used in WordPress is not secure in versions up to 4.0.1. This is because there is a problem with the way it checks for a specific code to protect against fake requests. This allows ...

    Read More
  • Access violation vulnerability in Stream 3.0.5

    Fixed

    The Stream plugin for WordPress is not secure in versions up to 3.0.5. This means that someone who has not been given permission could gain access to information that should be kept secret, such as l...

    Read More
  • Access violation vulnerability in Stream 3.9.3

    Fixed

    The Stream plugin for WordPress is not secure in versions up to and including 3.9.2. This means that people with a subscriber-level account or higher could access information that they should not be a...

    Read More
  • Input validation vulnerability in Stream 3.9.2

    Fixed

    The Stream plugin for WordPress has a security issue in versions up to 3.9.2. Exploiting this issue allows someone who isn't authenticated (doesn't have an account) to make a fake request to the websi...

    Read More
  • Input validation vulnerability in Stream 3.8.1

    Fixed

    The Stream plugin for WordPress had a security flaw before version 3.8.2 that allowed attackers to inject malicious code into the website. This was because the plugin did not properly check the inform...

    Read More
  • Access violation vulnerability in Stream 3.9.1

    Fixed

    The Stream plugin for WordPress has a security flaw that could let people with limited user access get access to sensitive information. This vulnerability affects users of all versions up to 3.9.1

    Read More