Redux Framework WordPress Plugin Privilege Escalation Vulnerability

Vulnerability

A privilege escalation vulnerability has been identified in the Redux Framework WordPress plugin, affecting versions prior to 4.5.13. The issue arises because the plugin does not properly restrict which user meta keys can be written when saving custom profile fields. This flaw allows users with at least the Subscriber role to escalate their privileges to Administrator by submitting a crafted value while updating their own profile. The vulnerability is present on sites where the plugin's user-profile feature is enabled.

Impact

Exploitation of this vulnerability allows users with the Subscriber role to gain Administrator privileges.

Remediation

Users are advised to update the Redux Framework WordPress plugin to version 4.5.13 or later.

Added: Jul 16, 2026, 7:26 AM
Updated: Jul 16, 2026, 7:26 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.6
remediation
0.0
relevance
9.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.