PT-2026-95802 · WordPress · Redux Framework
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Redux Framework versions prior to 4.5.14
Description
Stored Cross-Site Scripting occurs via the spinner field due to insufficient input sanitization and output escaping. In the
user meta save() function, scalar values bypass sanitization logic intended for arrays, allowing the spinner field value to be stored in user meta. This value is subsequently rendered in an unquoted HTML attribute within the render() function of class-redux-spinner.php via the line $data string .= ' data-val=' . $this->value;. Authenticated attackers with subscriber-level access or higher can inject arbitrary web scripts that execute when a user accesses the affected page.Recommendations
Update Redux Framework to version 4.5.14 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Redux Framework