Astra Security Suite – Firewall & Malware Scan <= 0.2 - Unauthenticated Arbitrary File Upload
high
The Astra Security Suite – Firewall & Malware Scan plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient validation of remote URLs for zip downloads and an easily guessable key in all versions up to, and including, 0.2. This makes it possible for unauthenticated attackers to upload arbitrary...
- CVSS:
- 8.1
- Affected:
- up to 0.2
- Fix:
- No patched version reported
- Disclosed:
- Nov 10, 2025
CVE-2025-11521 on NVD →
Astra Security Suite <= 0.2 - Missing Authorization
medium
The Astra Security Suite – Firewall & Malware Scan plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 0.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 0.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 1, 2025
CVE-2025-31774 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database