CVE-2025-14123
EUVD-2025-21105709.10.2026, 08:16
The Redux Framework plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.5.11. This is due to the plugin saving arbitrary meta keys under a registered option name without sufficient capability checks or key allowlist / restrictions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to set an arbitrary role (e.g., Administrator) when performing a profile update if a plugin or theme using this framework has added at least one user profile field that leverages Redux_Users::set_profile/set_section/set_field.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Common Weakness Enumeration