CVE-2026-12525
Deferred Deferred - Pending Action

Privilege Escalation in Redux Framework WordPress Plugin

Vulnerability report for CVE-2026-12525, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-16

Last updated on: 2026-07-16

Assigner: WPScan

Description

The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing users with at least the Subscriber role to escalate their privileges to Administrator by submitting a crafted value while updating their own profile, on sites where the Redux Framework WordPress plugin before 4.5.13's user-profile (Users extension) feature is enabled.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-16
Last Modified
2026-07-16
Generated
2026-08-05
AI Q&A
2026-07-16
EPSS Evaluated
2026-08-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redux_framework redux_framework to 4.5.13 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-12525 is a privilege escalation vulnerability in the Redux Framework WordPress plugin before version 4.5.13. It allows users with at least the Subscriber role to gain Administrator privileges by submitting a crafted value while updating their own profile. This occurs because the plugin does not restrict which user meta keys can be written when saving custom profile fields.

Detection Guidance

Check the installed version of the Redux Framework plugin in WordPress. If it is below 4.5.13, the system is vulnerable. Use WordPress admin panel or run a command like 'wp plugin list' in WP-CLI to verify the version.

Impact Analysis

If you are using the Redux Framework plugin before version 4.5.13 with the user-profile feature enabled, an attacker with a Subscriber role or higher could exploit this to gain full administrative access to your WordPress site. This could lead to complete site takeover, data theft, or further attacks.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements under GDPR and HIPAA. Unauthorized privilege escalation may result in data breaches, unauthorized modifications, or exposure of protected health or personal information, leading to legal and financial penalties.

Mitigation Strategies

Update the Redux Framework plugin to version 4.5.13 or later immediately. Disable the user-profile feature if not needed. Review user roles and privileges for any unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12525. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart