Impact
The vulnerability originates from inadequate sanitization when merging User Meta via the 'user-mediaurl' field. Consequently, an attacker can persist malicious script code in various user meta locations such as biography, session_tokens (through a crafted User‑Agent) or persisted_preferences (via the REST API). When a media URL repair is triggered on the demo panel, the data is to the site‑wide redux_demo option and rendered without proper escaping, allowing the injected code to execute in the context of any user who visits affected pages.
Affected Systems
Version 4.5.14 and earlier of the Redux Framework WordPress plugin authorised to users with Subscriber or higher roles are impacted. No other products are listed as affected.
Risk and Exploitability
The CVSS score of 6.4 places this issue in the medium severity range. EPSS data is not available, and the vulnerability is not included in the CISA KEV catalog. Attackers require only Subscriber‑level access, making the risk realistic for sites with many such users. The exploit path involves storing a payload in user meta via the plugin’s interface or associated REST endpoints, triggering the media URL repair, and then visiting a page that renders the patched redux_demo option, where the script runs in the victim’s browser.
OpenCVE Enrichment