PT-2026-95789 · WordPress · Redux Framework
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Redux Framework versions prior to 4.5.14
Description
Stored Cross-Site Scripting occurs via Media field filter values. The issue stems from insufficient input sanitization of nested array values in the
user meta save() function and unsafe output of filter CSS values in the render() function without proper escaping. Authenticated attackers with subscriber-level access and above can inject arbitrary web scripts into pages, which execute when a user accesses the affected page.Recommendations
Update Redux Framework to version 4.5.14 or later.
As a temporary mitigation, restrict access to the
user meta save() and render() functions for users with subscriber-level permissions.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Redux Framework