{"error":0,"message":null,"data":{"name":"Redux Framework","plugin":"redux-framework","link":"https:\/\/wordpress.org\/plugins\/redux-framework\/","latest":"1788956760","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"c675df671262c389095f016a63426a7d14517fee7c980c5f685205537fe3fd29","name":"Redux Framework [redux-framework] < 4.2.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.2.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-38312","name":"CVE-2021-38312","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-38312","description":"[en] The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress used an incorrect authorization check in the REST API endpoints registered under the \u201credux\/v1\/templates\/\u201d REST Route in \u201credux-templates\/classes\/class-api.php\u201d. The `permissions_callback` used in this file only checked for the `edit_posts` capability which is granted to lower-privileged users such as contributors, allowing such users to install arbitrary plugins from the WordPress repository and edit arbitrary posts.","date":"2021-09-02"},{"id":"3599591974d7b4e73da95aef0768ae87f96147ca","name":"Gutenberg Template Library & Redux Framework <= 4.2.1 - Incorrect Authorization Leading to Arbitrary Plugin Installation and Post Deletion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/redux-framework\/gutenberg-template-library-redux-framework-421-incorrect-authorization-leading-to-arbitrary-plugin-installation-and-post-deletion","description":"The Gutenberg Template Library & Redux Framework plugin <= 4.2.12 for WordPress used an incorrect authorization check in the REST API endpoints registered under the \u201credux\/v1\/templates\/\u201d REST Route in \u201credux-templates\/classes\/class-api.php\u201d. The `permissions_callback` used in this file only checked for the `edit_posts` capability which is granted to lower-privileged users such as contributors, allowing such users to install arbitrary plugins from the WordPress repository and edit arbitrary posts.","date":"2021-09-01"},{"id":"e690b887-de5f-4950-bedf-4a9f5fe9b773","name":"Gutenberg Template Library &amp; Redux Framework &lt; 4.2.13 - Contributor+ Arbitrary Plugin Installation and Post Deletion","link":"https:\/\/wpscan.com\/vulnerability\/e690b887-de5f-4950-bedf-4a9f5fe9b773","description":"The plugin did not correctly check the authorisation in the redux\/v1\/templates\/ REST API namespace, allowing any users with the edit_posts capability (ie contributor and above) to call the endpoints define in it. By using the redux\/v1\/templates\/plugin-install one, they could install plugins from the WordPres repository, or delete arbitrary posts\/pages via redux\/v1\/templates\/delete_saved_block","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:H\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"h","a":"n","score":"6.5","severity":"m","exploitable":"2.8","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:H\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"high","a":"none","exploitable":"2.8","impact":"3.6"},"cwe":[{"cwe":"CWE-280","name":"Improper Handling of Insufficient Permissions or Privileges","description":"The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state."},{"cwe":"CWE-863","name":"Incorrect Authorization","description":"The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"38faf58a6577c9a414abc40da5a95fb40c1ee0970af7631a31c31e86b898cc33","name":"Redux Framework [redux-framework] < 4.2.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.2.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-38314","name":"CVE-2021-38314","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-38314","description":"[en] The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions available to unauthenticated users in the `includes` function in `redux-core\/class-redux-core.php` that were unique to a given site but deterministic and predictable given that they were based on an md5 hash of the site URL with a known salt value of '-redux' and an md5 hash of the previous hash with a known salt value of '-support'. These AJAX actions could be used to retrieve a list of active plugins and their versions, the site's PHP version, and an unsalted md5 hash of site\u2019s `AUTH_KEY` concatenated with the `SECURE_AUTH_KEY`.","date":"2021-09-02"},{"id":"6ac3cc5f8e59bcf2970a2bd28e5bcc0ca6592f84","name":"WordPress Redux Framework plugin <= 4.2.11 - Incorrect Authorization Leading to Arbitrary Plugin Installation and Post Deletion vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/redux-framework\/vulnerability\/wordpress-redux-framework-plugin-4-2-11-incorrect-authorization-leading-to-arbitrary-plugin-installation-and-post-deletion-vulnerability","description":"Incorrect Authorization Leading to Arbitrary Plugin Installation and Post Deletion vulnerability discovered by Ramuel Gall (WordFence) in WordPress Redux Framework plugin (versions <= 4.2.11).","date":"2021-09-01"},{"id":"51eacf7403844b664c4c3e10307bdf2d24e39212","name":"WordPress Redux Framework plugin <= 4.2.11 - Sensitive Information Disclosure vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/redux-framework\/vulnerability\/wordpress-redux-framework-4-2-11-sensitive-information-disclosure-vulnerability","description":"Sensitive Information Disclosure vulnerability discovered by Ram Gall (WordFence) in WordPress Redux Framework plugin (versions <= 4.2.11).","date":"2021-09-01"},{"id":"2c919da7306b9d646c0eff386fe9ff867da0a8a7","name":"Gutenberg Template Library & Redux Framework <= 4.2.11 - Missing Authorization to Sensitive Information Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/redux-framework\/gutenberg-template-library-redux-framework-4211-missing-authorization-to-sensitive-information-disclosure","description":"The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions available to unauthenticated users in the `includes` function in `redux-core\/class-redux-core.php` that were unique to a given site but deterministic and predictable given that they were based on an md5 hash of the site URL with a known salt value of '-redux' and an md5 hash of the previous hash with a known salt value of '-support'. These AJAX actions could be used to retrieve a list of active plugins and their versions, the site's PHP version, and an unsalted md5 hash of site\u2019s `AUTH_KEY` concatenated with the `SECURE_AUTH_KEY`.","date":"2021-09-01"},{"id":"b6e6fa18-a292-49e1-a23b-d30606307455","name":"Gutenberg Template Library &amp; Redux Framework &lt; 4.2.13 - Unauthenticated Sensitive Information Disclosure","link":"https:\/\/wpscan.com\/vulnerability\/b6e6fa18-a292-49e1-a23b-d30606307455","description":"Some AJAX actions of the plugin, available to unauthenticated users and used for support features could allow attackers to obtain potentially sensitive information such as the PHP version, active plugins along with their versions, as well as the unsalted MD5 hashes of the site&rsquo;s AUTH_KEY and SECURE_AUTH_KEY.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."},{"cwe":"CWE-760","name":"Use of a One-Way Hash with a Predictable Salt","description":"The product uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product uses a predictable salt as part of the input."},{"cwe":"CWE-916","name":"Use of Password Hash With Insufficient Computational Effort","description":"The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"9f4ae1a9ea1a74dd3029c0d58643f3515e10c0797d869a4885159544fb31b0c6","name":"Redux Framework [redux-framework] < 4.1.21","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.21","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f15a2a490dbf42c0c78b7a45f164ce5b913e71eb","name":"WordPress Redux plugin <= 4.1.20 - Cross-Site Request Forgery (CSRF) Nonce Validation Bypass vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/redux-framework\/vulnerability\/wordpress-redux-plugin-4-1-20-cross-site-request-forgery-csrf-nonce-validation-bypass-vulnerability","description":"Cross-Site Request Forgery (CSRF) Nonce Validation Bypass vulnerability found by Lenon Leite (DevSoftIn) in  WordPress Redux plugin (versions <= 4.1.20).","date":"2020-12-15"}],"impact":[]},{"uuid":"fa9d5ce9ad65870d1aeb6d144df4f2b26150b37e76e565d5146a1e88bffb994e","name":"Redux Framework [redux-framework] >= 4.1.22 - <= 4.1.23","description":null,"operator":{"min_version":"4.1.22","min_operator":"ge","max_version":"4.1.23","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"54988723f7d346d1696d5c3a55e70e3860c8d074","name":"WordPress Redux Framework <= 4.1.23 - Cross-Site Request Forgery (CSRF) Nonce Validation Bypass vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/redux-framework\/vulnerability\/wordpress-redux-framework-4-1-23-cross-site-request-forgery-csrf-nonce-validation-bypass-vulnerability","description":"Cross-Site Request Forgery (CSRF) Nonce Validation Bypass vulnerability found by ErwanLR in WordPress Redux Framework (versions 4.1.22 - 4.1.23).","date":"2020-12-15"}],"impact":[]},{"uuid":"ae835476a8ea2d521502ee8acfe189682d5ac611b29d37da7bf66b929ab52148","name":"Redux Framework [redux-framework] < 4.1.21","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.21","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f356c909ba79aeed5e76da8351613e8d51fcd47a","name":"WordPress Redux Framework plugin <= 4.1.20 - CSRF Nonce Validation Bypass vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/redux-framework\/vulnerability\/wordpress-redux-framework-plugin-4-1-20-csrf-nonce-validation-bypass-vulnerability","description":"CSRF Nonce Validation Bypass vulnerability discovered by Lenon Leite in WordPress Redux Framework plugin (versions <= 4.1.20).","date":"2020-12-15"}],"impact":[]},{"uuid":"7e0ce322d57b5a5a153e41b6db8467ae0d267ca27ea763649b9a01b821f874b0","name":"Redux Framework [redux-framework] < 4.1.24","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.24","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"debaa4ac59d89352be34fbf13b9dfa0438587692","name":"Gutenberg Template Library & Redux Framework <= 4.1.23 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/redux-framework\/gutenberg-template-library-redux-framework-4123-cross-site-request-forgery","description":"The Gutenberg Template Library & Redux Framework plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.23. This is due to incorrect nonce validation in the 'Redux AJAX Save' class. This makes it possible for unauthenticated attackers to update the plugin's settings granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2020-12-15"}],"impact":[]},{"uuid":"8dc5b1a5ed202b13781bc7c5449fb301e797a08a9592b20ff5a4212807b52e7d","name":"Redux Framework [redux-framework] < 4.1.21","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.21","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"349264a834563d477ef1ae1e15fe44b9bbdb107b","name":"Gutenberg Template and Pattern Library & Redux Framework <= 4.1.20 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/redux-framework\/gutenberg-template-and-pattern-library-redux-framework-4120-cross-site-request-forgery","description":"The Gutenberg Template and Pattern Library & Redux Framework plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.20. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to modify settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2020-11-23"}],"impact":[]},{"uuid":"61a6e894681f3a00ffd9d74357487242a830fb2745b087bfdd44afe2246f702c","name":"Redux Framework [redux-framework] < 4.1.21","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.21","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"5d52b68f-faca-4572-bb84-ecb733eecbe7","name":"Redux Framework &lt; 4.1.21 - CSRF Nonce Validation Bypass","link":"https:\/\/wpscan.com\/vulnerability\/5d52b68f-faca-4572-bb84-ecb733eecbe7","description":"The plugin did not properly validate some nonces, only checking them if their value was set. As a result, CSRF attacks could still be performed by not submitting the nonce in the request, bypassing the protection they are supposed to provide.","date":null}],"impact":[]},{"uuid":"28f771ee595d6e71846268df97413e35665644dd2db2ae2c727a27a101c0faea","name":"Redux Framework [redux-framework] < 4.1.24","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.24","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ad9a190b-3bb6-4589-84e7-43372615588f","name":"Redux Framework 4.1.22 - 4.1.23 - CSRF Nonce Validation Bypass","link":"https:\/\/wpscan.com\/vulnerability\/ad9a190b-3bb6-4589-84e7-43372615588f","description":"The plugin re-introduced a CSRF bypass issue in v4.1.22, as the nonce is only checked if present in the request.","date":null}],"impact":[]},{"uuid":"c905db3cf2aa4eb7b83fb1ec7c7793c5d9fb2bfd652d2b48c6149b38e893fc4a","name":"Redux Framework [redux-framework] < 4.4.18","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.4.18","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-6828","name":"CVE-2024-6828","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-6828","description":"[en] The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization and capability checks on the Redux_Color_Scheme_Import function in versions 4.4.12 to 4.4.17. This makes it possible for unauthenticated attackers to upload JSON files, which can be used to conduct stored cross-site scripting attacks and, in some rare cases, when the wp_filesystem fails to initialize - to Remote Code Execution.","date":"2024-07-23"},{"id":"622cf4ee00c6282065d806d1f5df837fbc53896c","name":"Redux Framework 4.4.12 -  4.4.17 - Unauthenticated JSON File Upload to Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/redux-framework\/redux-framework-4412-4417-unauthenticated-json-file-upload-to-stored-cross-site-scripting","description":"The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization and capability checks on the Redux_Color_Scheme_Import function in versions 4.4.12 to 4.4.17. This makes it possible for unauthenticated attackers to upload JSON files, which can be used to conduct stored cross-site scripting attacks and, in some rare cases, when the wp_filesystem fails to initialize - to Remote Code Execution.","date":"2024-07-22"},{"id":"29e0ed862d397aedb9ff5e0a8a3d0c3eda56d931","name":"WordPress Redux Framework Plugin <= 4.4.17 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/redux-framework\/vulnerability\/wordpress-redux-framework-plugin-4-4-17-unauthenticated-json-file-upload-to-stored-cross-site-scripting-vulnerability","description":"<p>WordPress Redux Framework Plugin <= 4.4.17 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Redux Framework<\/p><p>Link: https:\/\/wordpress.org\/plugins\/redux-framework\/#developers<\/p><p>Affected Version <= 4.4.17<\/p><p>Fixed in version 4.4.18 <\/p>","date":"2024-07-22"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"7.2","severity":"h","exploitable":"3.9","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"7.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.9","impact":"2.7"},"cwe":[{"cwe":"CWE-434","name":"Unrestricted Upload of File with Dangerous Type","description":"The product allows the upload or transfer of dangerous file types that are automatically processed within its environment."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"ffa1ac4802f3ea0e091e7f7bd35142d4fea594199df1b4ef01441bcca0f977bb","name":"Redux Framework [redux-framework] < 4.5.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.5.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-9488","name":"Redux Framework <= 4.5.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via data Parameter","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-9488","description":"The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018data\u2019 parameter in all versions up to, and including, 4.5.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"8729ead35caebd35a9777f90e177cff8d2abf414","name":"Redux Framework <= 4.5.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via data Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/redux-framework\/redux-framework-458-authenticated-contributor-stored-cross-site-scripting-via-data-parameter","description":"The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018data\u2019 parameter in all versions up to, and including, 4.5.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-12-12"},{"id":"EUVD-2025-203202","name":"EUVD-2025-203202","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-203202","description":"The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018data\u2019 parameter in all versions up to, and including, 4.5.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-12-13"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":null,"impact":null}}},{"uuid":"017bf5eed311e943e7a5b25e34103ac086e462cf8f30aec70c91494b2859c98f","name":"Redux Framework [redux-framework] < 4.5.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.5.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-12525","name":"CVE-2026-12525","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-12525","description":"[en] The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing users with at least the Subscriber role to escalate their privileges to Administrator by submitting a crafted value while updating their own profile, on sites where the Redux Framework WordPress plugin before 4.5.13's user-profile (Users extension) feature is enabled.","date":"2026-07-16"},{"id":"01843af0facef3e680f69c87fb7d02d8c1a4bab9","name":"Redux Framework <= 4.5.12 - Authenticated (Subscriber+) Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/4c498789-79f4-4b79-8e55-57eab1c51d4e","description":"The Redux Framework plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.5.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to an administrator when the users extension is enabled.","date":"2026-06-25"}],"impact":{"cwe":[{"cwe":"CWE-269","name":"Improper Privilege Management","description":"The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"a2318d97f5c9de3bd760d7a711c233f116a227914b8b10e44fd04d99b1dd8262","name":"Redux Framework [redux-framework] < 4.5.14","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.5.14","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-5399","name":"CVE-2026-5399","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-5399","description":"[en] The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Slider field in User Profile settings in versions up to and including 4.5.13.1. This is due to insufficient input sanitization in the user_meta_save() function (which only sanitizes array values, not scalar values) and improper output escaping in the Redux_Slider::render() method, which outputs slider values into unquoted HTML attributes. The vulnerability also exploits the fact that the clean_default() method only casts values to numeric types when they are empty or out of bounds, allowing malicious strings like '1 tabindex=0 autofocus onfocus=alert(1) x=' to pass validation through PHP's loose type comparison. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts into their user profile that will execute whenever an Administrator navigates to view the attacker's profile page.","date":"2026-09-10"},{"id":"b53902a6e938f1e8a9a71adf2ebb25aed708c6ca","name":"Redux Framework <= 4.5.13.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Slider Field Value","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/redux-framework\/redux-framework-45131-authenticated-subscriber-stored-cross-site-scripting-via-slider-field-value","description":"The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Slider field in User Profile settings in versions up to and including 4.5.13.1. This is due to insufficient input sanitization in the user_meta_save() function (which only sanitizes array values, not scalar values) and improper output escaping in the Redux_Slider::render() method, which outputs slider values into unquoted HTML attributes. The vulnerability also exploits the fact that the clean_default() method only casts values to numeric types when they are empty or out of bounds, allowing malicious strings like '1 tabindex=0 autofocus onfocus=alert(1) x=' to pass validation through PHP's loose type comparison. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts into their user profile that will execute whenever an Administrator navigates to view the attacker's profile page.","date":"2026-06-25"},{"id":"a49635ba7332d3ef6ee1d18ae24928afa46e674e","name":"WordPress Redux Framework Plugin <= 4.5.13.1 is vulnerable to a medium priority Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/redux-framework\/vulnerability\/wordpress-redux-framework-plugin-4-5-13-1-authenticated-subscriber-stored-cross-site-scripting-vulnerability","description":"<p>WordPress Redux Framework Plugin <= 4.5.13.1 is vulnerable to a medium priority Cross Site Scripting (XSS)<\/p><p>Software: Redux Framework<\/p><p>Fixed in version 4.5.14 <\/p><p>Affected Version <= 4.5.13.1<\/p><p>CVE: CVE-2026-5399<\/p>","date":"2026-09-10"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"74f42507175edc240e4b07fd4c159a6c6791bbaa1218cda4f188a29b0ca088aa","name":"Redux Framework [redux-framework] < 4.5.14","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.5.14","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-5400","name":"CVE-2026-5400","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-5400","description":"[en] The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media field filter values in versions up to, and including, 4.5.13 This is due to insufficient input sanitization of nested array values in the user_meta_save() function and unsafe output of filter CSS values in the render() function without proper escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-09-19"},{"id":"d7350ad23988192ed3419863d6e82a67482007f9","name":"Redux Framework <= 4.5.13 - Authenticated (Subscriber+) Cross-Site Scripting via User Input","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/redux-framework\/redux-framework-4513-authenticated-subscriber-cross-site-scripting-via-user-input","description":"The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media field filter values in versions up to, and including, 4.5.13 This is due to insufficient input sanitization of nested array values in the user_meta_save() function and unsafe output of filter CSS values in the render() function without proper escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-09-18"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"43ab80b5bd155058c3ff4a5737148167d4f7d02f0c22580fbd2324b5bafb96b3","name":"Redux Framework [redux-framework] < 4.5.14","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.5.14","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-5410","name":"CVE-2026-5410","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-5410","description":"[en] The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the spinner field in versions up to, and including, 4.5.13 This is due to insufficient input sanitization and output escaping. In the user_meta_save() function scalar values bypass the sanitization logic that only processes arrays, allowing the spinner field value to be stored in user meta without proper sanitization. Later, at line 56 of class-redux-spinner.php in the render() function, this value is rendered in an unquoted HTML attribute without escaping via '$data_string .= ' data-val=' . $this->value;'. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-09-19"},{"id":"16a7df2304e8ba21d07a2c6affe6d7f3501ad32c","name":"Redux Framework <= 4.5.13 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Spinner Field Input","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/redux-framework\/redux-framework-4513-authenticated-subscriber-stored-cross-site-scripting-via-spinner-field-input","description":"The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the spinner field in versions up to, and including, 4.5.13 This is due to insufficient input sanitization and output escaping. In the user_meta_save() function scalar values bypass the sanitization logic that only processes arrays, allowing the spinner field value to be stored in user meta without proper sanitization. Later, at line 56 of class-redux-spinner.php in the render() function, this value is rendered in an unquoted HTML attribute without escaping via '$data_string .= ' data-val=' . $this->value;'. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-09-18"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1789802916"}