Astra
Astra has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 3 are fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.4 out of 10. 2024 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 3 of the records (100%).
Every one of the 3 issues recorded for Astra has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, one record each. Astra is installed on roughly 1,000,000 WordPress sites, so each unpatched flaw has a wide blast radius.
CVE-2026-3534Astra <= 4.12.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta
Read the full analysisVulnerability Records

The Astra WordPress theme is lightning-fast and highly customizable. It has over 1 million downloads and the only theme in the world with 6,000+ five-star reviews! It’s ideal for professional web designers, solopreneurs, small businesses, eCommerce, membership sites and any type of website. It offers special features and templates so it works perfectly with all page builders like Spectra, Elementor, Beaver Builder, etc. Fast performance, clean code, mobile-first design and schema markup are all built-in, making the theme exceptionally SEO-friendly. It’s fully compatible with WooCommerce, SureCart and other eCommerce plugins and comes with lots of store-friendly features and templates. Astra also provides expert support for free users. A dedicated team of fully trained WordPress experts are on hand to help with every aspect of the theme. Try the live demo of Astra: https://zipwp.org/themes/astra/
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C