Stored Cross-Site Scripting in Redux Framework Plugin for WordPress
CVE-2026-90992
6.4MEDIUM
What is CVE-2026-90992?
The Redux Framework plugin for WordPress suffers from a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping mechanisms. Authenticated users with Subscriber-level access can exploit this vulnerability, allowing them to inject arbitrary scripts into user meta fields, including biography and session tokens. These malicious scripts may then execute when any user accesses the affected pages. The exploit can be initiated via crafted User-Agent strings or through the REST API, making it imperative for site administrators to update to version 4.5.15 or later to mitigate this risk.
Affected Version(s)
Redux Framework 0 <= 4.5.14