medium · CVSS v3 6.4
CVE-2026-90992
The Redux Framework plugin for WordPress is vulnerable to stored XSS via user meta merge. Authenticated users with Subscriber role can injec
Overview
The Redux Framework plugin for WordPress is vulnerable to stored XSS via user meta merge. Authenticated users with Subscriber role can inject scripts that execute on site pages. This can lead to defacement or credential theft.
Description
The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User Meta Merge via 'user-mediaurl' Media Field in all versions up to, and including, 4.5.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by Subscriber-level users who can store a payload in user meta fields such as the biography, session_tokens (via a crafted User-Agent at login), or persisted_preferences (via the REST API), which are then promoted to the site-wide redux_demo option when a media URL repair is triggered on the demo panel.
Impact
Confidentiality: attackers can steal session cookies. Integrity: site content can be altered. Availability: minimal. Defenders: site admins, developers, security teams.
Remediation
Upgrade Redux Framework to version 4.5.15 or later. If upgrade not possible, restrict Subscriber role from editing user meta fields or disable media URL repair feature. Apply input sanitization on user-meta fields and escape output.
Risk context
Medium severity; no EPSS data; recommend prompt patching.
Affected products
- WordPress
- Redux Framework plugin
- Redux Framework 4.5.14
Scores
- Severity
- medium
- CVSS v2
- 5.5
- CVSS v3
- 6.4
- CVSS v4
- —
- EPSS
- —