Arbitrary File Upload Vulnerability in Astra Security Suite Plugin for WordPress
CVE-2025-11521

8.1HIGH

What is CVE-2025-11521?

The Astra Security Suite – Firewall & Malware Scan plugin for WordPress is exposed to a vulnerability that allows unauthenticated attackers to perform arbitrary file uploads due to inadequate validation of remote URLs for ZIP file downloads. This flaw stems from the use of a poorly secured key, present in all versions up to and including 0.2. If exploited, this vulnerability can enable attackers to upload malicious files to the server, potentially leading to remote code execution, thereby compromising the security of the affected site.

Affected Version(s)

Astra Security Suite – Firewall & Malware Scan * <= 0.2

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kenneth Dunn
.
CVE-2025-11521 : Arbitrary File Upload Vulnerability in Astra Security Suite Plugin for WordPress