VYPR

Redux Framework

by WordPress

Source repositories

CVEs (8)

  • CVE-2024-6828HigJul 23, 2024
    risk 0.47cvss 7.2epss 0.01

    The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization and capability checks on the Redux_Color_Scheme_Import function in versions 4.4.12 to 4.4.17. This makes it possible for unauthenticated attackers to upload…

  • CVE-2025-9488MedDec 13, 2025
    risk 0.42cvss 6.4epss 0.00

    The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data’ parameter in all versions up to, and including, 4.5.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2026-90992MedOct 1, 2026
    risk 0.35cvss 6.4epss —

    The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User Meta Merge via 'user-mediaurl' Media Field in all versions up to, and including, 4.5.14 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-5410MedSep 19, 2026
    risk 0.35cvss 6.4epss 0.00

    The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the spinner field in versions up to, and including, 4.5.13 This is due to insufficient input sanitization and output escaping. In the user_meta_save() function scalar values bypass the…

  • CVE-2026-5400MedSep 19, 2026
    risk 0.35cvss 6.4epss 0.00

    The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media field filter values in versions up to, and including, 4.5.13 This is due to insufficient input sanitization of nested array values in the user_meta_save() function and unsafe…

  • CVE-2026-5399MedSep 10, 2026
    risk 0.35cvss 6.4epss 0.00

    The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Slider field in User Profile settings in versions up to and including 4.5.13.1. This is due to insufficient input sanitization in the user_meta_save() function (which only sanitizes…

  • CVE-2026-88999MedOct 1, 2026
    risk 0.21cvss 4.3epss —

    The Redux Framework plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.14 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with…

  • CVE-2026-12525HigJul 16, 2026
    risk 0.00cvss 8.8epss 0.00

    The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing users with at least the Subscriber role to escalate their privileges to Administrator by submitting a crafted value while updating…