WP Vulnerability WatchVulnerability data as of October 1, 2026

Vulnerability alerts / September 30, 2026

Vulnerability in Astra — CVE-2026-27085

LowSeverity
CVSS 2.7
—Estimated exploit probability
EPSS
1,000,000+ sitesInstalls
4.14.0Fixed in

What to do now

Update Astra to 4.14.0 or later.

Affected versions

  • Everything up to and including 4.13.12

Affected: Astra (theme, astra)

Check: The theme on wordpress.org / Our record for Astra

What the vulnerability is

Shop manager Content Injection in Astra WordPress Theme <= 4.13.12 versions.

This description is reproduced verbatim from the public vulnerability record.

Sources

This page is compiled automatically from public databases. Accuracy is not guaranteed; confirm against the vendor advisory before acting.

See other alerts