SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-12525

HIGH · CVSS 8.8 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Redux Framework plugin for WordPress prior to version 4.5.13 is vulnerable due to insufficient restrictions on user meta key modifications, enabling users with Subscriber roles to escalate their privileges to Administrator by manipulating their profile updates. This vulnerability poses a significant risk to site security, particularly for installations with the user-profile feature enabled. WordPress site administrators using this plugin should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-12525
Severity
HIGH
CVSS
8.8
EPSS
0.23%
WordPress

Original NVD Description

The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing users with at least the Subscriber role to escalate their privileges to Administrator by submitting a crafted value while updating their own profile, on sites where the Redux Framework WordPress plugin before 4.5.13's user-profile (Users extension) feature is enabled.