WordPress security changelog
MEDIUM CVE-2026-5399 Deferred

Redux Framework stores subscriber scripts in profile sliders

Redux Framework through 4.5.13.1 accepts scalar slider values in user_meta_save() without sanitizing them. clean_default() can preserve malicious strings through loose numeric comparisons, and Redux_Slider::render() places those values in unquoted attributes. A Subscriber or higher-privileged user can store script-bearing profile values that execute when an Administrator views that profile.

CVE / CNA score 6.4 CVSS 3.1 · security@wordfence.com
NVD score Pending NVD has not published its own CVSS assessment.
Component
Redux Framework
Plugin slug
redux-framework
Affected
<= 4.5.13.1
Safe version
See mitigation notes
Published
Sep 10, 2026
Weakness
CWE-79 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

This CVE was published Sep 10, 2026 and is one of 7 known issues for this plugin.

Update, patch or deactivate.

Redux Framework 4.5.14 is available and may resolve this issue, but the checked official changelog does not confirm a matching fix. Update and obtain vendor confirmation. If in doubt, contact Fused or your hosting vendor.

No confirmed safe version is listed. Consider a vendor-supported patch or temporarily restricting the affected functionality while you assess the risk.

Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.

Technical description

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Slider field in User Profile settings in versions up to and including 4.5.13.1. This is due to insufficient input sanitization in the user_meta_save() function (which only sanitizes array values, not scalar values) and improper output escaping in the Redux_Slider::render() method, which outputs slider values into unquoted HTML attributes. The vulnerability also exploits the fact that the clean_default() method only casts values to numeric types when they are empty or out of bounds, allowing malicious strings like '1 tabindex=0 autofocus onfocus=alert(1) x=' to pass validation through PHP's loose type comparison. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts into their user profile that will execute whenever an Administrator navigates to view the attacker's profile page.

CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Primary and upstream sources