Davidanderson Redux Framework vulnerabilities
2 known vulnerabilities affecting davidanderson/redux_framework.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2024-6828P2HIGHCVSS 7.2Exploited≥ 4.4.12, ≤ 4.4.172024-07-23
CVE-2024-6828 [HIGH] CWE-434 CVE-2024-6828: The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to m
The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization and capability checks on the Redux_Color_Scheme_Import function in versions 4.4.12 to 4.4.17. This makes it possible for unauthenticated attackers to upload JSON files, which can be used to conduct stored cross-site scripting attacks
nvd
CVE-2025-9488P4MEDIUMCVSS 6.4≤ 4.5.82025-12-13
CVE-2025-9488 [MEDIUM] CWE-79 CVE-2025-9488: The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data’
The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data’ parameter in all versions up to, and including, 4.5.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that
nvd