CVE-2026-27085
Received Received - Intake

Shop Manager Content Injection in Astra WordPress Theme

Vulnerability report for CVE-2026-27085, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Patchstack

Description

Shop manager Content Injection in Astra WordPress Theme <= 4.13.12 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
astra wordpress_theme to 4.13.12 (inc)
brainstorm_force astra to 4.13.12 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-80 The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Content Injection issue in the WordPress Astra Theme versions 4.13.12 or earlier. It allows attackers with low-level privileges, such as a Shop Manager, to inject unwanted content like ads, scams, or malware links into web pages.

Detection Guidance

Check the installed version of the Astra WordPress Theme. If it is 4.13.12 or earlier, the system is vulnerable. Use WordPress admin panel or run: wp theme list --fields=name,version | grep astra

Impact Analysis

Attackers could inject malicious or unwanted content into your website, potentially harming visitors or damaging your site's reputation. The risk is considered low due to the minimal CVSS score of 2.7.

Mitigation Strategies

Update the Astra WordPress Theme to version 4.14.0 or later immediately. If updating is not possible, contact your hosting provider or a web developer for assistance.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-27085. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart