The Stream WordPress plugin prior to 3.9.2 does not prevent users with little privileges on the site (like subscribers) from using its alert creation functionality, which may enable them to leak sensitive information.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
xwp stream |