CVE-2026-90992: Redux Framework <= 4.5.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'user-mediaurl' Media Field
The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User Meta Merge via 'user-mediaurl' Media Field in all versions up to, and including, 4.5.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by Subscriber-level users who can store a payload in user meta fields such as the biography, sessiontokens (via a crafted User-Agent at login), or persistedpreferences (via the REST API), which are then promoted to the site-wide reduxdemo option when a media URL repair is triggered on the demo panel.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated WordPress user with Subscriber-level access or higher can exploit it. The attacker does not need interaction from the eventual victim, but a user must later access the page containing the injected content for the script to execute.
What attacker-controlled data can be used to store the payload?
The payload can be stored in user meta fields, including the biography, session_tokens through a crafted User-Agent during login, or persisted_preferences through the REST API. A media URL repair triggered on the demo panel promotes this data into the site-wide redux_demo option.
Are sites affected by default?
Exploitation requires the media URL repair process to be triggered on the demo panel. The provided information does not establish that this occurs in a default configuration.
How can I determine whether my site may be affected?
Review whether Redux Framework version 4.5.14 or earlier is installed and whether untrusted Subscriber-or-higher accounts exist. Investigate the redux_demo option and relevant user meta fields for unexpected script-like content, particularly after demo-panel media URL repairs.