Impact
The Redux Framework plugin for WordPress contains a stored cross‑site scripting flaw located in the spinner field handling. Because scalar values bypass the sanitization routine, an attacker who can log in with Subscriber or higher role can submit malicious script code that is saved directly to user metadata. The data is later interpolated into an unquoted HTML attribute in the render() function, so the malicious script runs in any page that includes the spinner field. This flaw satisfies CWE‑79 and can compromise the integrity and confidentiality of the site for any user that views the affected page.
Affected Systems
All installations of the Redux Framework plugin for WordPress with versions 4.5.13 or older are vulnerable. The flaw is present in the core library files class‑redux‑extension‑users.php and class‑redux‑spinner.php. Administrators should assess whether their sites use any of these versions and whether subscriber‑level users can edit spinner fields.
Risk and Exploitability
The published CVSS score of 6.4 indicates a moderate severity. The EPSS score of less than 1% shows that the expected exploitation rate is small, and the flaw is not in the CISA KEV catalog. Nevertheless, any authenticated subscriber can inject script code; exploitation requires only the ability to edit the spinner field and does not need additional credentials. The script executes in the victim browser context when the affected page is loaded, enabling data exfiltration, cookie theft, or session hijacking. Because the vulnerability is stored, impact is limited to pages where the spinner field is rendered but does not allow arbitrary code execution on the server side.
OpenCVE Enrichment