Arbitrary File Upload Vulnerability in Astra Security Suite Plugin for WordPress
CVE-2025-11521
8.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 November 2025
What is CVE-2025-11521?
The Astra Security Suite – Firewall & Malware Scan plugin for WordPress is exposed to a vulnerability that allows unauthenticated attackers to perform arbitrary file uploads due to inadequate validation of remote URLs for ZIP file downloads. This flaw stems from the use of a poorly secured key, present in all versions up to and including 0.2. If exploited, this vulnerability can enable attackers to upload malicious files to the server, potentially leading to remote code execution, thereby compromising the security of the affected site.
Affected Version(s)
Astra Security Suite – Firewall & Malware Scan * <= 0.2