← WordPress Vulnerabilities
WordPress security by component

Redux Framework

Redux Framework provides a framework for creating and managing settings panels used by WordPress themes and plugins.

Redux Framework (redux-framework) is a WordPress plugin with 7 published CVE records in this archive. The latest tracked vulnerability was published Oct 01, 2026; the highest published CVSS base score is 8.8.

Plugin slug: redux-framework

CVE-2026-88999: Redux Framework: Subscriber deletion of other users' media attachments

The Redux Framework plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.14 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary media library attachments, including administrator-owned files, from the affected site. This is exploitable by Subscribers when a Custom Fonts field is registered on the user profile page via Redux_Users::set_profile(), as doing so causes the required redux_custom_fonts nonce to be rendered into the Subscriber's wp-admin/profile.php page. The official changelog confirms a matching fix in 4.5.15.

PublishedOct 01, 2026
Known safe version4.5.15
Published vulnerabilities for redux-framework
Safe version
Oct 01, 2026 CVE-2026-88999
Redux Framework: Subscriber deletion of other users' media attachments
The Redux Framework plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.14 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary media library attachments, including administrator-owned files, from the affected site. This is exploitable by Subscribers when a Custom Fonts field is registered on the user profile page via Redux_Users::set_profile(), as doing so causes the required redux_custom_fonts nonce to be rendered into the Subscriber's wp-admin/profile.php page. The official changelog confirms a matching fix in 4.5.15.
4.5.15
CVE4.3
NVDPending
Sep 19, 2026 CVE-2026-5410
Redux spinner user metadata escapes into an unquoted HTML attribute
A Subscriber or higher role submits a scalar spinner value. user_meta_save() only sanitizes arrays, leaving that scalar stored unfiltered. The spinner render() method in class-redux-spinner.php then places it in an unquoted data-val attribute, permitting stored script when the affected UI is viewed. The exact save route is not disclosed. Authoritative affected range: <= 4.5.13. No fixed release is confirmed in this review.
See mitigation notes
CVE6.4
NVDPending
Sep 19, 2026 CVE-2026-5400
Redux Media filter values become stored script
A Subscriber or higher role can store malicious nested Media-field values because user_meta_save() does not sanitize those nested arrays sufficiently. The render() method then emits filter CSS values without appropriate escaping, allowing script when affected output is viewed. The exact request route and nested key are not disclosed. Authoritative affected range: <= 4.5.13. No fixed release is confirmed in this review.
See mitigation notes
CVE6.4
NVDPending
Sep 10, 2026 CVE-2026-5399
Redux Framework stores subscriber scripts in profile sliders
Redux Framework through 4.5.13.1 accepts scalar slider values in user_meta_save() without sanitizing them. clean_default() can preserve malicious strings through loose numeric comparisons, and Redux_Slider::render() places those values in unquoted attributes. A Subscriber or higher-privileged user can store script-bearing profile values that execute when an Administrator views that profile.
See mitigation notes
CVE6.4
NVDPending
Jul 16, 2026 CVE-2026-12525
Redux Framework: A security weakness
Redux Framework is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 4.5.13.
4.5.13
CVE8.8
NVDPending
Dec 13, 2025 CVE-2025-9488
Redux Framework: Cross-site scripting
Redux Framework is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Jul 23, 2024 CVE-2024-6828
Redux Framework: Cross-site scripting
Redux Framework is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVDPending