Redux Framework
Redux Framework provides a framework for creating and managing settings panels used by WordPress themes and plugins.
Redux Framework (redux-framework) is a WordPress plugin with 7 published CVE records in this archive. The latest tracked vulnerability was published Oct 01, 2026; the highest published CVSS base score is 8.8.
redux-frameworkCVE-2026-88999: Redux Framework: Subscriber deletion of other users' media attachments
The Redux Framework plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.14 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary media library attachments, including administrator-owned files, from the affected site. This is exploitable by Subscribers when a Custom Fonts field is registered on the user profile page via Redux_Users::set_profile(), as doing so causes the required redux_custom_fonts nonce to be rendered into the Subscriber's wp-admin/profile.php page. The official changelog confirms a matching fix in 4.5.15.
| Safe version |
|
||
|---|---|---|---|
| Oct 01, 2026 |
CVE-2026-88999
Redux Framework: Subscriber deletion of other users' media attachments
The Redux Framework plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.14 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary media library attachments, including administrator-owned files, from the affected site. This is exploitable by Subscribers when a Custom Fonts field is registered on the user profile page via Redux_Users::set_profile(), as doing so causes the required redux_custom_fonts nonce to be rendered into the Subscriber's wp-admin/profile.php page. The official changelog confirms a matching fix in 4.5.15.
|
4.5.15 |
CVE4.3
NVDPending
|
| Sep 19, 2026 |
CVE-2026-5410
Redux spinner user metadata escapes into an unquoted HTML attribute
A Subscriber or higher role submits a scalar spinner value. user_meta_save() only sanitizes arrays, leaving that scalar stored unfiltered. The spinner render() method in class-redux-spinner.php then places it in an unquoted data-val attribute, permitting stored script when the affected UI is viewed. The exact save route is not disclosed. Authoritative affected range: <= 4.5.13. No fixed release is confirmed in this review.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Sep 19, 2026 |
CVE-2026-5400
Redux Media filter values become stored script
A Subscriber or higher role can store malicious nested Media-field values because user_meta_save() does not sanitize those nested arrays sufficiently. The render() method then emits filter CSS values without appropriate escaping, allowing script when affected output is viewed. The exact request route and nested key are not disclosed. Authoritative affected range: <= 4.5.13. No fixed release is confirmed in this review.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Sep 10, 2026 |
CVE-2026-5399
Redux Framework stores subscriber scripts in profile sliders
Redux Framework through 4.5.13.1 accepts scalar slider values in user_meta_save() without sanitizing them. clean_default() can preserve malicious strings through loose numeric comparisons, and Redux_Slider::render() places those values in unquoted attributes. A Subscriber or higher-privileged user can store script-bearing profile values that execute when an Administrator views that profile.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Jul 16, 2026 |
CVE-2026-12525
Redux Framework: A security weakness
Redux Framework is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 4.5.13.
|
4.5.13 |
CVE8.8
NVDPending
|
| Dec 13, 2025 |
CVE-2025-9488
Redux Framework: Cross-site scripting
Redux Framework is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Jul 23, 2024 |
CVE-2024-6828
Redux Framework: Cross-site scripting
Redux Framework is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVDPending
|