Arbitrary File Upload Vulnerability in Astra Security Suite Plugin for WordPress
CVE-2025-11521
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 November 2025
What is CVE-2025-11521?
The Astra Security Suite β Firewall & Malware Scan plugin for WordPress is exposed to a vulnerability that allows unauthenticated attackers to perform arbitrary file uploads due to inadequate validation of remote URLs for ZIP file downloads. This flaw stems from the use of a poorly secured key, present in all versions up to and including 0.2. If exploited, this vulnerability can enable attackers to upload malicious files to the server, potentially leading to remote code execution, thereby compromising the security of the affected site.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Astra Security Suite β Firewall & Malware Scan * <= 0.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved