Impact
The Redux Framework WordPress plugin before version 4.5.13 fails to restrict which user meta keys can be written when a user saves custom profile fields. This unfiltered write allows a user with at least the Subscriber role to submit a crafted payload while updating their own profile, thereby granting themselves the Administrator role and fully elevating their privileges on the site. The flaw is an improper restriction of operations within a trusted context, identified as CWE‑269.
Affected Systems
WordPress installations that have the Redux Framework plugin installed at any version earlier than 4.5.13 and that have the user‑profile (Users extension) feature enabled are affected. The vendor is Redux Framework, the product is the WordPress plugin, and affected releases include all builds prior to 4.5.13.
Risk and Exploitability
The vulnerability receives a CVSS score of 8.8, indicating a high severity. The EPSS score of less than 1% suggests that exploitation is not common but still possible; the issue is not yet listed in CISA’s KEV catalog. Because the attack requires only a valid subscriber account and the ability to submit a profile update, the likely exploitation vector is a low‑privilege authenticated user performing a standard profile‑change action. An attacker can elevate privileges to administrator without needing any additional system access or remote exploitation tools.
OpenCVE Enrichment