{"id":"CVE-2026-5400","summary":"Redux Framework \u003c= 4.5.13 - Authenticated (Subscriber+) Cross-Site Scripting via User Input","details":"The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media field filter values in versions up to, and including, 4.5.13 This is due to insufficient input sanitization of nested array values in the user_meta_save() function and unsafe output of filter CSS values in the render() function without proper escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","modified":"2026-09-20T11:46:41.008750627Z","published":"2026-09-19T07:43:19.874Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5400.json","cna_assigner":"Wordfence","cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://github.com/reduxframework/redux-framework/pull/4112/changes"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.5.10/redux-core/inc/extensions/users/class-redux-extension-users.php#L1034"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.5.10/redux-core/inc/fields/media/class-redux-media.php#L233"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.5.10/redux-core/inc/fields/media/class-redux-media.php#L337"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/redux-framework/trunk/redux-core/inc/extensions/users/class-redux-extension-users.php#L1034"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/redux-framework/trunk/redux-core/inc/fields/media/class-redux-media.php#L233"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/redux-framework/trunk/redux-core/inc/fields/media/class-redux-media.php#L337"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/changeset/3688279/redux-framework/trunk/redux-core/inc/fields/media/class-redux-media.php"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/changeset?reponame=&new=3688279%40redux-framework%2Ftags%2F4.5.14&old=3582185%40redux-framework%2Ftags%2F4.5.13"},{"type":"WEB","url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca5b1ff6-19c5-4384-ae63-faf1f40122e7?source=cve"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5400.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5400"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/reduxframework/redux-framework","events":[{"introduced":"0"},{"last_affected":"ebdaa9f0a5a5dd0cba9e12ecc83598b39b879be2"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"4.5.13"}],"source":"AFFECTED_FIELD"}}],"versions":["4.5.13","4.5.12","4.5.11","4.5.10","4.5.9","4.5.8","4.5.7","4.5.6","4.5.4","4.5.3","4.5.2","4.5.1","4.5.0","4.4.18","4.4.17","4.4.16","4.4.15","4.4.14","4.4.13","4.4.12","4.4.11","4.4.10","4.4.9","4.4.8","4.4.7","4.4.6","4.4.5","4.4.4","4.4.3","4.4.2","4.4.1","4.4.0","4.3.26","4.3.25","4.3.24","4.3.22","4.3.21","4.3.20","4.3.19","4.3.18","4.3.17","4.3.16","4.3.15","4.3.14","4.3.13","4.3.12","4.3.11","4.3.10","4.3.9","4.3.8","4.3.7","4.3.5","4.3.4","4.3.3","4.3.2","4.3.1","4.3.0","4.2.14","4.2.13","4.2.12","4.2.11","4.2.10","4.2.9","4.2.8","4.2.7","4.2.6","4.2.5","4.2.4","4.2.3","4.2.2","4.2.1","4.2.0","4.1.29","4.1.28","3.6.18","3.6.17","3.6.16","3.6.15","3.6.5","3.6.0.1","3.5.9","3.5.7","3.5.5","3.5.1","3.5.0","3.4.3.6","3.4.0","3.3.9.4","3.3.8","3.3.6","3.5.5.10","3.3.4","3.3.3","3.3.1.1","3.3.0","3.2.9.13","3.2.9","3.2.8","3.2.6","3.2.5","3.2.4","3.2.3","3.2.2","3.2.1","3.1.9","3.1.8","3.1.6","3.1.4","3.1.3","3.1.2","3.1.0","3.0.9","3.0.8","3.0.7","3.0.6","3.0.5","3.0.4","3.0.0-beta"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-5400.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"}]}