theme

Astra Vulnerabilities

4 known security issues reported for the Astra WordPress theme. Most recent disclosed Mar 10, 2026.

4 medium

Running Astra on your site? Check whether your installed version is affected.

Scan your site free

Astra WordPress Theme - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta vulnerability

medium

Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta vulnerability

CVSS:
6.5
Affected:
up to 4.12.3
Fixed in:
4.12.4
Disclosed:
Mar 10, 2026

Astra <= 4.12.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta

medium

The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `ast-page-background-meta` and `ast-content-background-meta` post meta fields in all versions up to, and including, 4.12.3. This is due to insufficient input sanitization on meta registration and missing output escaping in the `astra_get...

CVSS:
6.4
Affected:
up to 4.12.3
Fixed in:
4.12.4
Disclosed:
Mar 10, 2026

CVE-2026-3534 on NVD →

Astra <= 4.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Display Name

medium

The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name in all versions up to, and including, 4.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary we...

CVSS:
6.4
Affected:
up to 4.6.8
Fixed in:
4.6.9
Disclosed:
Mar 25, 2024

CVE-2024-2347 on NVD →

Astra <= 4.6.4 - Authenticated (Editor+) Stored Cross-Site Scripting via Theme Header/Footer

medium

The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme header and footer content in all versions up to, and including, 4.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access, to inject arbitrary web...

CVSS:
5.5
Affected:
up to 4.6.4
Fixed in:
4.6.5
Disclosed:
Mar 25, 2024

CVE-2024-29768 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database