CVE · Critical

CVE-2023-49830 — Astra Pro Addon [astra-addon] < 4.3.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-49830 Astra Pro Addon [astra-addon] < 4.3.2 Improper Control of Generation of Code ('Code Injection') Critical 9.9 < 4.3.2 4.3.2 2023-12-05

CVE-2023-49830

A Remote Code Execution flaw was discovered in the Astra Pro plugin before version 4.3.2 that could permit an attacker to run arbitrary commands on an affected website. Successful exploitation of this vulnerability could enable an attacker to establish backdoor access and obtain complete control over the site. The issue has been patched in version 4.3.2 and later releases. Users should update their installations to the latest available version to mitigate this risk.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.