Stored Cross-Site Scripting in Redux Framework Plugin for WordPress
CVE-2026-90992

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 October 2026

What is CVE-2026-90992?

The Redux Framework plugin for WordPress suffers from a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping mechanisms. Authenticated users with Subscriber-level access can exploit this vulnerability, allowing them to inject arbitrary scripts into user meta fields, including biography and session tokens. These malicious scripts may then execute when any user accesses the affected pages. The exploit can be initiated via crafted User-Agent strings or through the REST API, making it imperative for site administrators to update to version 4.5.15 or later to mitigate this risk.

Affected Version(s)

Redux Framework 0 <= 4.5.14

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daroo
.