Brainstormforce Astra
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Brainstormforce Astra.
By the Year
In 2026 there have been 1 vulnerability in Brainstormforce Astra with an average score of 6.4 out of ten. Astra did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 1 | 6.40 |
| 2025 | 0 | 0.00 |
| 2024 | 3 | 7.60 |
| 2023 | 1 | 8.80 |
| 2022 | 0 | 0.00 |
| 2021 | 1 | 9.80 |
It may take a day or so for new Astra vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Brainstormforce Astra Security Vulnerabilities
Astra WP Theme <=4.12.3 Stored XSS via ast-page/ast-content meta
CVE-2026-3534
6.4 - Medium
- March 11, 2026
The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `ast-page-background-meta` and `ast-content-background-meta` post meta fields in all versions up to, and including, 4.12.3. This is due to insufficient input sanitization on meta registration and missing output escaping in the `astra_get_responsive_background_obj()` function for four CSS-context sub-properties (`background-color`, `background-image`, `overlay-color`, `overlay-gradient`). This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
Missing Auth in Brainstorm Force Astra Bulk Edit 1.2.7
CVE-2023-44148
8.8 - High
- June 19, 2024
Missing Authorization vulnerability in Brainstorm Force Astra Bulk Edit.This issue affects Astra Bulk Edit: from n/a through 1.2.7.
AuthZ
Astra WP Theme <=4.6.8 XSS via display name injection
CVE-2024-2347
6.4 - Medium
- April 09, 2024
The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name in all versions up to, and including, 4.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
WordPress Astra Stored XSS pre-4.6.4 (CVE-2024-29768)
CVE-2024-29768
- March 27, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra allows Stored XSS.This issue affects Astra: from n/a through 4.6.4.
XSS
Astra Pro <4.3.2 Code Injection via Improper Code Generation
CVE-2023-49830
8.8 - High
- December 29, 2023
Improper Control of Generation of Code ('Code Injection') vulnerability in Brainstorm Force Astra Pro.This issue affects Astra Pro: from n/a through 4.3.1.
Code Injection
The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters
CVE-2021-24507
9.8 - Critical
- August 09, 2021
The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both unauthenticated and authenticated user) before using them in SQL statement, leading to an SQL Injection issues
SQL Injection
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Brainstormforce Astra or by Brainstormforce? Click the Watch button to subscribe.