CVE-2025-11521

HIGH

Astra Security Suite - Firewall & Malware Scan <0.3 - RCE

Title source: llm
STIX 2.1

Description

The Astra Security Suite – Firewall & Malware Scan plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient validation of remote URLs for zip downloads and an easily guessable key in all versions up to, and including, 0.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

Scores

CVSS v3 8.1
EPSS 0.0042
EPSS Percentile 33.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-285
Status published
Products (1)
astrasecuritysuite/Astra Security Suite – Firewall & Malware Scan < 0.2
Published Nov 11, 2025
Tracked Since Feb 18, 2026