Stored Cross-Site Scripting in Redux Framework for WordPress
CVE-2026-5400
6.4MEDIUM
What is CVE-2026-5400?
The Redux Framework plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input sanitization in the user_meta_save() function and unsafe output handling in the render() function. This vulnerability allows authenticated users with subscriber-level access and higher to inject malicious web scripts into pages. When these pages are accessed, the scripts execute, compromising the security of the affected WordPress site.
Affected Version(s)
Redux Framework 0 <= 4.5.13