What the vulnerability does
01Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Brainstorm Force Astra Pro.This issue affects Astra Pro: from n/a through 4.3.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Improper Control of Generation of Code ('Code Injection') vulnerability in Brainstorm Force Astra Pro.This issue affects Astra Pro: from n/a through 4.3.1.
Explanation of Vulnerability in Simple Terms
Astra Pro versions up to 4.3.1 contain a code injection vulnerability that allows authenticated users with low privileges to inject and execute arbitrary PHP code on the site. The vulnerability affects the entire site scope due to the nature of code execution. An attacker with a low-privilege account can modify site behavior, access sensitive data, or take control of the WordPress installation.
What an attacker can do
Run arbitrary PHP code on the site with full site access and control.
Potential impact on your site
A compromised low-privilege user account can lead to complete site takeover, data theft, or malware injection.
Conditions required to exploit
Attacker must have a low-privilege authenticated account (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities