plugin

Redux Framework Vulnerabilities

17 known security issues reported for the Redux Framework WordPress plugin. Most recent disclosed Jun 25, 2026.

4 high 3 medium

Running Redux Framework on your site? Check whether your installed version is affected.

Scan your site free

Redux Framework <= 4.5.12 - Authenticated (Subscriber+) Privilege Escalation

high

The Redux Framework plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.5.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to an administrator when the users extension is enabled.

CVSS:
8.8
Affected:
up to 4.5.12
Fixed in:
4.5.13
Disclosed:
Jun 25, 2026

CVE-2026-12525 on NVD →

Redux Framework <= 4.5.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via data Parameter

medium

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data’ parameter in all versions up to, and including, 4.5.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject ar...

CVSS:
6.4
Affected:
up to 4.5.8
Fixed in:
4.5.9
Disclosed:
Dec 12, 2025

CVE-2025-9488 on NVD →

Redux Framework [redux-framework] < 4.4.18

unknown

[en] The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization and capability checks on the Redux_Color_Scheme_Import function in versions 4.4.12 to 4.4.17. This makes it possible for unauthenticated attackers to upload JSON files, which can be used to cond...

Affected:
up to 4.4.18
Fixed in:
4.4.18
Disclosed:
Jul 23, 2024

CVE-2024-6828 on NVD →

Redux Framework 4.4.12 - 4.4.17 - Unauthenticated JSON File Upload to Stored Cross-Site Scripting

high

The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization and capability checks on the Redux_Color_Scheme_Import function in versions 4.4.12 to 4.4.17. This makes it possible for unauthenticated attackers to upload JSON files, which can be used to conduct s...

CVSS:
7.2
Affected:
4.4.12 – 4.4.17
Fixed in:
4.4.18
Disclosed:
Jul 22, 2024

CVE-2024-6828 on NVD →

Redux Framework [redux-framework] < 4.2.13

unknown

[en] The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress used an incorrect authorization check in the REST API endpoints registered under the “redux/v1/templates/” REST Route in “redux-templates/classes/class-api.php”. The `permissions_callback` used in this file only checked for the `edit_p...

Affected:
up to 4.2.13
Fixed in:
4.2.13
Disclosed:
Sep 2, 2021

CVE-2021-38312 on NVD →

Redux Framework [redux-framework] < 4.2.13

unknown

[en] The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions available to unauthenticated users in the `includes` function in `redux-core/class-redux-core.php` that were unique to a given site but deterministic and predictable given that they were based on an md5...

Affected:
up to 4.2.13
Fixed in:
4.2.13
Disclosed:
Sep 2, 2021

CVE-2021-38314 on NVD →

Gutenberg Template Library & Redux Framework <= 4.2.1 - Incorrect Authorization Leading to Arbitrary Plugin Installation and Post Deletion

high

The Gutenberg Template Library & Redux Framework plugin <= 4.2.12 for WordPress used an incorrect authorization check in the REST API endpoints registered under the “redux/v1/templates/” REST Route in “redux-templates/classes/class-api.php”. The `permissions_callback` used in this file only checked for the `edit_posts`...

CVSS:
7.1
Affected:
up to 4.2.12
Fixed in:
4.2.13
Disclosed:
Sep 1, 2021

CVE-2021-38312 on NVD →

Gutenberg Template Library & Redux Framework <= 4.2.11 - Missing Authorization to Sensitive Information Disclosure

medium

The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions available to unauthenticated users in the `includes` function in `redux-core/class-redux-core.php` that were unique to a given site but deterministic and predictable given that they were based on an md5 hash...

CVSS:
5.3
Affected:
up to 4.2.11
Fixed in:
4.2.13
Disclosed:
Sep 1, 2021

CVE-2021-38314 on NVD →

Gutenberg Template Library & Redux Framework <= 4.1.23 - Cross-Site Request Forgery

medium

The Gutenberg Template Library & Redux Framework plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.23. This is due to incorrect nonce validation in the 'Redux AJAX Save' class. This makes it possible for unauthenticated attackers to update the plugin's settings grant...

CVSS:
5.3
Affected:
up to 4.1.24
Fixed in:
4.1.24
Disclosed:
Dec 15, 2020

Redux Framework [redux-framework] < 4.1.21

unknown

Cross-Site Request Forgery (CSRF) Nonce Validation Bypass vulnerability found by Lenon Leite (DevSoftIn) in WordPress Redux plugin (versions <= 4.1.20).

Affected:
up to 4.1.21
Fixed in:
4.1.21
Disclosed:
Dec 15, 2020

Redux Framework [redux-framework] >= 4.1.22 - <= 4.1.23

unknown

Cross-Site Request Forgery (CSRF) Nonce Validation Bypass vulnerability found by ErwanLR in WordPress Redux Framework (versions 4.1.22 - 4.1.23).

Affected:
4.1.22 – 4.1.23
Fixed in:
4.1.23
Disclosed:
Dec 15, 2020

Redux Framework [redux-framework] < 4.1.21

unknown

CSRF Nonce Validation Bypass vulnerability discovered by Lenon Leite in WordPress Redux Framework plugin (versions <= 4.1.20).

Affected:
up to 4.1.21
Fixed in:
4.1.21
Disclosed:
Dec 15, 2020

Redux Framework [redux-framework] < 4.1.24

unknown

The Gutenberg Template Library & Redux Framework plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.23. This is due to incorrect nonce validation in the 'Redux AJAX Save' class. This makes it possible for unauthenticated attackers to update the plugin's settings grant...

Affected:
up to 4.1.24
Fixed in:
4.1.24
Disclosed:
Dec 15, 2020

Gutenberg Template and Pattern Library & Redux Framework <= 4.1.20 - Cross-Site Request Forgery

high

The Gutenberg Template and Pattern Library & Redux Framework plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.20. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to modify settings via...

CVSS:
8.8
Affected:
up to 4.1.20
Fixed in:
4.1.21
Disclosed:
Nov 23, 2020

Redux Framework [redux-framework] < 4.1.21

unknown

The Gutenberg Template and Pattern Library & Redux Framework plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.20. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to modify settings via...

Affected:
up to 4.1.21
Fixed in:
4.1.21
Disclosed:
Nov 23, 2020

Redux Framework [redux-framework] < 4.1.21

unknown

The plugin did not properly validate some nonces, only checking them if their value was set. As a result, CSRF attacks could still be performed by not submitting the nonce in the request, bypassing the protection they are supposed to provide.

Affected:
up to 4.1.21
Fixed in:
4.1.21

Redux Framework [redux-framework] < 4.1.24

unknown

The plugin re-introduced a CSRF bypass issue in v4.1.22, as the nonce is only checked if present in the request.

Affected:
up to 4.1.24
Fixed in:
4.1.24

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database