Impact
The Redux Framework plugin for WordPress allows authenticated users with Subscriber-level or higher privileges to upload arbitrary meta keys under a registered option name because the plugin does not enforce proper capability checks or key restrictions. An attacker can leverage user profile fields that use Redux_Users::set_profile, set_section, or set_field to inject an arbitrary role such as Administrator when updating their profile. This flaw can elevate a low‑privilege user directly to a full‑admin role, compromising the integrity and confidentiality of the site.
Affected Systems
All releases of the Redux Framework plugin up to and including version 4.5.11 are affected. The vulnerability manifests in any WordPress installation that loads the Redux Framework plugin, particularly when a theme or another plugin has added custom user profile fields that invoke the vulnerable Redux_Users methods. The plugin is developed by David Anderson.
Risk and Exploitability
With a CVSS score of 6.8, the threat is considered moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, implying no confirmed widespread exploitation yet. Nevertheless, because the flaw requires only a logged‑in Subscriber account and a standard profile‑update action, it can be triggered by any authenticated attacker who has access to the site. The lack of a restriction on role assignment during the update makes the attack straightforward, and the impact of achieving Administrator privileges is severe for the website owner.
OpenCVE Enrichment