Software intelligence
Important: Stream appearing in this catalog does not mean your website is affected. Exposure depends on your installed version. How SiteRespond intelligence works
Tracked advisories
8
Latest advisory
6 August 2026
CISA KEV matches
0
In this WordPress feed
WordPress slug
stream
Plugin
This catalog lists 8 known advisories affecting Stream. The most recent was published on 6 August 2026. If you use this software, compare your installed version against the affected ranges on each advisory and update to a fixed release outside those ranges. SiteRespond Defence checks your actual installed version when the plugin is connected — listing here does not by itself mean your site is vulnerable.
Stream <= 4.2.0 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via Heartbeat API
This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.
Published 6 August 2026
Stream <= 4.0.2 - Authenticated (Admin+) Server-Side Request Forgery
This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.
Published 14 February 2025
Stream <= 4.0.1 - Cross-Site Request Forgery to Arbitrary Options Update
May trick authenticated users into performing unintended actions.
Published 12 September 2024
Known Stream advisories published by month.
CVE-2026-11907 · Published 6 August 2026
Affected versions: ≤ 4.2.0
CVE-2024-13879 · Published 14 February 2025
Affected versions: ≤ 4.0.2
CVE-2024-7423 · Published 12 September 2024
Affected versions: ≤ 4.0.1
CVE-2022-43450 · Published 25 April 2023
Affected versions: < 3.9.3
CVE-2022-43490 · Published 18 April 2023
Affected versions: ≤ 3.9.2
CVE-2022-4384 · Published 16 January 2023
Affected versions: ≤ 3.9.1
CVE-2021-24772 · Published 18 October 2021
Affected versions: ≤ 3.8.1
No CVE assigned · Published 31 May 2016
Affected versions: ≤ 3.0.5
SiteRespond Defence matches your installed Stream version against this catalog when the Defence plugin is connected to your WordPress site.