Impact
The Redux Framework plugin for WordPress up to version 4.5.13 contains a stored cross‑site scripting flaw that allows authenticated users with subscriber level or higher roles to insert arbitrary JavaScript into the Media field filter values because nested array data is not sanitized in user_meta_save() and filter CSS values are output without proper escaping in render(), enabling the script to execute whenever the page renders the affected field.
Affected Systems
All installations of the Redux Framework WordPress plugin with a version of 4.5.13 or earlier are affected; any site where users have subscriber or higher roles can exploit this vulnerability.
Risk and Exploitability
With a CVSS score of 6.4, the issue is of medium severity, and the EPSS score of less than 1 % indicates a very low current exploitation probability; the vulnerability is not listed in the CISA KEV catalog, and authenticate to the WordPress site with a subscriber or higher role to inject the script, after which it will run for all visitors to the page displaying the Media field.
OpenCVE Enrichment