Privilege Escalation Vulnerability in Redux Framework for WordPress
CVE-2025-14123
6.8MEDIUM
What is CVE-2025-14123?
The Redux Framework plugin for WordPress has a vulnerability that allows authenticated attackers, even those with only Subscriber-level access, to escalate their privileges. This flaw is due to the plugin's improper handling of meta keys, which it saves under a registered option name without adequate checks or restrictions. As a consequence, attackers can set arbitrary user roles (like Administrator) when updating profile fields, particularly if the framework is utilized by a theme or plugin that includes custom user profile fields.
Affected Version(s)
Redux Framework 0 <= 4.5.11