CVE-2026-90992: Redux Framework <= 4.5.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'user-mediaurl' Media Field

Published Oct 1, 2026
·
Updated

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User Meta Merge via 'user-mediaurl' Media Field in all versions up to, and including, 4.5.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by Subscriber-level users who can store a payload in user meta fields such as the biography, sessiontokens (via a crafted User-Agent at login), or persistedpreferences (via the REST API), which are then promoted to the site-wide reduxdemo option when a media URL repair is triggered on the demo panel.

Affected Software

1 affected component
wordpress/redux-framework<=4.5.14

Event History

Oct 1, 2026
CVE Published
via MITRE·08:28 AM
Data Sourced
via MITRE·08:28 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated WordPress user with Subscriber-level access or higher can exploit it. The attacker does not need interaction from the eventual victim, but a user must later access the page containing the injected content for the script to execute.

2

What attacker-controlled data can be used to store the payload?

The payload can be stored in user meta fields, including the biography, session_tokens through a crafted User-Agent during login, or persisted_preferences through the REST API. A media URL repair triggered on the demo panel promotes this data into the site-wide redux_demo option.

3

Are sites affected by default?

Exploitation requires the media URL repair process to be triggered on the demo panel. The provided information does not establish that this occurs in a default configuration.

4

How can I determine whether my site may be affected?

Review whether Redux Framework version 4.5.14 or earlier is installed and whether untrusted Subscriber-or-higher accounts exist. Investigate the redux_demo option and relevant user meta fields for unexpected script-like content, particularly after demo-panel media URL repairs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203