Description
The Redux Framework plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.5.11. This is due to the plugin saving arbitrary meta keys under a registered option name without sufficient capability checks or key allowlist / restrictions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to set an arbitrary role (e.g., Administrator) when performing a profile update if a plugin or theme using this framework has added at least one user profile field that leverages Redux_Users::set_profile/set_section/set_field.
Published: 2026-10-09
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Update
AI Analysis

Impact

The Redux Framework plugin for WordPress allows authenticated users with Subscriber-level or higher privileges to upload arbitrary meta keys under a registered option name because the plugin does not enforce proper capability checks or key restrictions. An attacker can leverage user profile fields that use Redux_Users::set_profile, set_section, or set_field to inject an arbitrary role such as Administrator when updating their profile. This flaw can elevate a low‑privilege user directly to a full‑admin role, compromising the integrity and confidentiality of the site.

Affected Systems

All releases of the Redux Framework plugin up to and including version 4.5.11 are affected. The vulnerability manifests in any WordPress installation that loads the Redux Framework plugin, particularly when a theme or another plugin has added custom user profile fields that invoke the vulnerable Redux_Users methods. The plugin is developed by David Anderson.

Risk and Exploitability

With a CVSS score of 6.8, the threat is considered moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, implying no confirmed widespread exploitation yet. Nevertheless, because the flaw requires only a logged‑in Subscriber account and a standard profile‑update action, it can be triggered by any authenticated attacker who has access to the site. The lack of a restriction on role assignment during the update makes the attack straightforward, and the impact of achieving Administrator privileges is severe for the website owner.

Generated by OpenCVE AI on October 9, 2026 at 09:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Redux Framework plugin to version 4.5.12 or later, which removes the unrestricted meta key writes.
  • Remove any user profile fields in themes or plugins that call Redux_Users::set_profile, set_section, or set_field; disable or eliminate custom fields that are not required for site operation.
  • Apply the principle of least privilege by ensuring that only users with the Administrator role can modify other users' meta fields or add custom profile fields, and review capability checks in any custom code that interfaces with Redux Framework.

Generated by OpenCVE AI on October 9, 2026 at 09:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description The Redux Framework plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.5.11. This is due to the plugin saving arbitrary meta keys under a registered option name without sufficient capability checks or key allowlist / restrictions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to set an arbitrary role (e.g., Administrator) when performing a profile update if a plugin or theme using this framework has added at least one user profile field that leverages Redux_Users::set_profile/set_section/set_field.
Title Redux Framework <= 4.5.11 – Authenticated (Subscriber+) Privilege Escalation via Users Extension
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-09T07:41:48.079Z

Reserved: 2025-12-05T16:32:56.932Z

Link: CVE-2025-14123

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-09T08:16:54.090

Modified: 2026-10-09T13:20:48.273

Link: CVE-2025-14123

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T09:30:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management