CVE-2025-14123: Redux Framework <= 4.5.11 – Authenticated (Subscriber+) Privilege Escalation via Users Extension
The Redux Framework plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.5.11. This is due to the plugin saving arbitrary meta keys under a registered option name without sufficient capability checks or key allowlist / restrictions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to set an arbitrary role (e.g., Administrator) when performing a profile update if a plugin or theme using this framework has added at least one user profile field that leverages ReduxUsers::setprofile/setsection/setfield.
Affected Software
Event History
Frequently Asked Questions
Which sites are actually exposed to this issue?
A site is exposed only if it uses Redux Framework 4.5.11 or earlier and a plugin or theme using the framework has added at least one user-profile field through Redux_Users::set_profile, set_section, or set_field.
What access does an attacker need?
The attacker must already be authenticated with Subscriber-level access or higher. Exploitation occurs during a profile update and can be used to assign an arbitrary role, including Administrator.
Is this exploitable by unauthenticated visitors?
No. The available information identifies the issue as requiring authenticated access with at least the Subscriber role.