Wpstream is a narrowly scoped vendor focused on a single streaming product, with the durable exposure concentrated in cross-site request forgery weaknesses affecting request-handling logic. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpstream over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-68522HIGH Missing Authorization vulnerability in wpstream WpStream wpstream allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpStream: from n/a thro | Dec 24, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-68521HIGH Missing Authorization vulnerability in wpstream WpStream wpstream allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpStream: from n/a thro | Dec 24, 2025 | 8.8 | 27 | NO | NO |
CVE-2023-27458HIGH Cross-Site Request Forgery (CSRF) vulnerability in wpstream WpStream plugin <= 4.4.10 versions. | Nov 22, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-38512HIGH Cross-Site Request Forgery (CSRF) vulnerability in wpstream WpStream wpstream allows Cross Site Request Forgery.This issue affects WpStream: from n/a through <= 4.5.4. | Jul 27, 2023 | 8.8 | 23 | NO | NO |
CVE-2026-39526MEDIUM Authorization Bypass Through User-Controlled Key vulnerability in wpstream WpStream wpstream allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affe | Apr 8, 2026 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpstream.
Media articles that mention a CVE ID that affects a product developed by Wpstream — matched by CVE ID, not by vendor name.