Description
The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User Meta Merge via 'user-mediaurl' Media Field in all versions up to, and including, 4.5.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by Subscriber-level users who can store a payload in user meta fields such as the biography, session_tokens (via a crafted User-Agent at login), or persisted_preferences (via the REST API), which are then promoted to the site-wide redux_demo option when a media URL repair is triggered on the demo panel.
Published: 2026-10-01
Score: 6.4 Medium
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting in Redux Framework that allows authenticated users with Subscriber level or higher to inject arbitrary scripts into site pages
Action: Apply Patch
AI Analysis

Impact

The vulnerability originates from inadequate sanitization when merging User Meta via the 'user-mediaurl' field. Consequently, an attacker can persist malicious script code in various user meta locations such as biography, session_tokens (through a crafted User‑Agent) or persisted_preferences (via the REST API). When a media URL repair is triggered on the demo panel, the data is to the site‑wide redux_demo option and rendered without proper escaping, allowing the injected code to execute in the context of any user who visits affected pages.

Affected Systems

Version 4.5.14 and earlier of the Redux Framework WordPress plugin authorised to users with Subscriber or higher roles are impacted. No other products are listed as affected.

Risk and Exploitability

The CVSS score of 6.4 places this issue in the medium severity range. EPSS data is not available, and the vulnerability is not included in the CISA KEV catalog. Attackers require only Subscriber‑level access, making the risk realistic for sites with many such users. The exploit path involves storing a payload in user meta via the plugin’s interface or associated REST endpoints, triggering the media URL repair, and then visiting a page that renders the patched redux_demo option, where the script runs in the victim’s browser.

Generated by OpenCVE AI on October 1, 2026 at 11:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Redux Framework to a version newer than 4.5.14 or apply the official 4.5.15 release that addresses the sanitization issue.
  • If an update is not immediately possible, disable the media URL repair feature in the demo panel and limit Subscriber+ roles from editing user meta fields that may be rendered by the plugin.
  • Sanitize and escape any user‑supplied meta data stored by the plugin; use WordPress utilities such as wp_kses() or esc_html() before outputting.

Generated by OpenCVE AI on October 1, 2026 at 11:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Davidanderson
Davidanderson redux Framework
Wordpress-extensions
Wordpress-extensions redux Framework
Vendors & Products Davidanderson
Davidanderson redux Framework
Wordpress-extensions
Wordpress-extensions redux Framework

Thu, 01 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User Meta Merge via 'user-mediaurl' Media Field in all versions up to, and including, 4.5.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by Subscriber-level users who can store a payload in user meta fields such as the biography, session_tokens (via a crafted User-Agent at login), or persisted_preferences (via the REST API), which are then promoted to the site-wide redux_demo option when a media URL repair is triggered on the demo panel.
Title Redux Framework <= 4.5.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'user-mediaurl' Media Field
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Davidanderson Redux Framework
Wordpress-extensions Redux Framework
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-01T18:25:50.057Z

Reserved: 2026-09-14T14:30:20.066Z

Link: CVE-2026-90992

cve-icon Vulnrichment

Updated: 2026-10-01T18:24:35.542Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T09:17:09.927

Modified: 2026-10-01T19:17:25.497

Link: CVE-2026-90992

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:36:24Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')