Astra WordPress Theme - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta vulnerability
medium
Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta vulnerability
- CVSS:
- 6.5
- Affected:
- up to 4.12.3
- Fixed in:
- 4.12.4
- Disclosed:
- Mar 10, 2026
Astra <= 4.12.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta
medium
The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `ast-page-background-meta` and `ast-content-background-meta` post meta fields in all versions up to, and including, 4.12.3. This is due to insufficient input sanitization on meta registration and missing output escaping in the `astra_get...
- CVSS:
- 6.4
- Affected:
- up to 4.12.3
- Fixed in:
- 4.12.4
- Disclosed:
- Mar 10, 2026
CVE-2026-3534 on NVD →
Astra <= 4.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Display Name
medium
The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name in all versions up to, and including, 4.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary we...
- CVSS:
- 6.4
- Affected:
- up to 4.6.8
- Fixed in:
- 4.6.9
- Disclosed:
- Mar 25, 2024
CVE-2024-2347 on NVD →
Astra <= 4.6.4 - Authenticated (Editor+) Stored Cross-Site Scripting via Theme Header/Footer
medium
The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme header and footer content in all versions up to, and including, 4.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access, to inject arbitrary web...
- CVSS:
- 5.5
- Affected:
- up to 4.6.4
- Fixed in:
- 4.6.5
- Disclosed:
- Mar 25, 2024
CVE-2024-29768 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database