Impact
The Streamit WordPress theme contains insufficient file validation in the function that handles download requests, enabling users with subscriber-level or higher access to download any file on the server. This flaw falls under input validation and path traversal weaknesses (CWE‑22) and could allow attackers to exfiltrate private data or internal configuration files. The impact is limited to confidentiality loss, as the flaw does not modify or execute code on the host.
Affected Systems
The vulnerability affects the iqonicdesign Streamit theme for WordPress in all versions up to and including 4.0.1. Users must verify whether their site is running a version in this range.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity and the EPSS score of less than 1% suggests a very low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog, and it requires authenticated access at the subscriber level or higher, meaning only users who have logged in with those privileges can exploit it. However, once authenticated, attackers can retrieve arbitrary files, so the overall risk to a site depends on the sensitivity of the data behind those files.
OpenCVE Enrichment
EUVD