VYPR

Astra

by WordPress

CVEs (3)

  • CVE-2026-3534MedMar 11, 2026
    risk 0.42cvss 6.4epss 0.00

    The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `ast-page-background-meta` and `ast-content-background-meta` post meta fields in all versions up to, and including, 4.12.3. This is due to insufficient input sanitization on meta registration and…

  • CVE-2024-2347MedApr 9, 2024
    risk 0.42cvss 6.4epss 0.00

    The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name in all versions up to, and including, 4.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

  • CVE-2024-29768MedMar 27, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra allows Stored XSS.This issue affects Astra: from n/a through 4.6.4.