CVE-2026-27085: WordPress Astra WordPress theme theme <= 4.13.12 - Content Injection vulnerability
Published Sep 30, 2026
·Updated
Shop manager Content Injection in Astra WordPress Theme <= 4.13.12 versions.
Affected Software
1 affected component
Brainstorm Force Astra WordPress Theme<=4.13.12
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Astra WordPress Themeto a version that resolves this vulnerability.Fixed in 4.14.0
Event History
Sep 30, 2026
CVE Published
via MITRE·12:26 PM
Data Sourced
via MITRE·12:26 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs Shop Manager privileges in WordPress. The available information does not indicate that unauthenticated or lower-privileged users can exploit it.
2
What is the impact of successful exploitation?
Successful exploitation can result in content injection. The reported CVSS vector indicates integrity impact only, with no reported confidentiality or availability impact.
3
Which Astra versions are affected?
Astra WordPress Theme versions up to and including 4.13.12 are identified as affected.