CVE-2026-12525: Redux Framework < 4.5.13 - Subscriber+ Privilege Escalation to Administrator
The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing users with at least the Subscriber role to escalate their privileges to Administrator by submitting a crafted value while updating their own profile, on sites where the Redux Framework WordPress plugin before 4.5.13's user-profile (Users extension) feature is enabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Redux Framework WordPress pluginto a version that resolves this vulnerability.Fixed in 4.5.13 - Configuration
If you cannot upgrade immediately, ensure the Redux Framework users/profile feature does not allow saving custom profile fields to arbitrary user meta keys for users with at least the Subscriber role.
Redux Framework WordPress plugin (Users extension) user-profile (custom profile fields) permission to write user meta keys = Restrict writable user meta keys to only those required
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12525?
CVE-2026-12525 has a risk score of 71.
How do I fix CVE-2026-12525?
To fix CVE-2026-12525, update the Redux Framework WordPress plugin to version 4.5.13 or later.
What type of vulnerability is CVE-2026-12525?
CVE-2026-12525 is a privilege escalation vulnerability affecting the Redux Framework WordPress plugin.
Who is affected by CVE-2026-12525?
Users with at least the Subscriber role in the Redux Framework WordPress plugin are affected by CVE-2026-12525.
What action can exploit CVE-2026-12525?
Submitting a crafted value while updating their own profile allows users to escalate privileges to Administrator.