{"id":"CVE-2026-88999","summary":"Redux Framework \u003c= 4.5.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Deletion via 'attachment_id' Parameter","details":"The Redux Framework plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.14 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary media library attachments, including administrator-owned files, from the affected site. This is exploitable by Subscribers when a Custom Fonts field is registered on the user profile page via Redux_Users::set_profile(), as doing so causes the required redux_custom_fonts nonce to be rendered into the Subscriber's wp-admin/profile.php page.","modified":"2026-10-03T03:30:14.841505911Z","published":"2026-10-01T05:30:55.556Z","database_specific":{"cna_assigner":"Wordfence","cwe_ids":["CWE-862"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88999.json"},"references":[{"type":"WEB","url":"https://github.com/reduxframework/redux-framework/pull/4117/changes"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.5.13/redux-core/inc/extensions/custom_fonts/class-redux-extension-custom-fonts.php#L338"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.5.13/redux-core/inc/extensions/custom_fonts/class-redux-extension-custom-fonts.php#L392"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.5.13/redux-core/inc/extensions/custom_fonts/class-redux-extension-custom-fonts.php#L571"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.5.13/redux-core/inc/extensions/custom_fonts/class-redux-extension-custom-fonts.php#L617"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.5.13/redux-core/inc/extensions/custom_fonts/custom_fonts/class-redux-custom-fonts.php#L57"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.5.14/redux-core/inc/extensions/custom_fonts/class-redux-extension-custom-fonts.php#L338"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.5.14/redux-core/inc/extensions/custom_fonts/class-redux-extension-custom-fonts.php#L392"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.5.14/redux-core/inc/extensions/custom_fonts/class-redux-extension-custom-fonts.php#L571"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.5.14/redux-core/inc/extensions/custom_fonts/class-redux-extension-custom-fonts.php#L617"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.5.14/redux-core/inc/extensions/custom_fonts/custom_fonts/class-redux-custom-fonts.php#L57"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/changeset/3705066/redux-framework/trunk/redux-core/inc/extensions/custom_fonts/class-redux-extension-custom-fonts.php"},{"type":"WEB","url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c7e24790-01a0-41bc-a380-60d86c6e1443?source=cve"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88999.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88999"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/reduxframework/redux-framework","events":[{"introduced":"0"},{"last_affected":"c7df8b857b2c20eeffdbfed3d2fbb8ca86952440"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"4.5.14"}],"source":"AFFECTED_FIELD"}}],"versions":["4.5.14","4.5.13","4.5.12","4.5.11","4.5.10","4.5.9","4.5.8","4.5.7","4.5.6","4.5.4","4.5.3","4.5.2","4.5.1","4.5.0","4.4.18","4.4.17","4.4.16","4.4.15","4.4.14","4.4.13","4.4.12","4.4.11","4.4.10","4.4.9","4.4.8","4.4.7","4.4.6","4.4.5","4.4.4","4.4.3","4.4.2","4.4.1","4.4.0","4.3.26","4.3.25","4.3.24","4.3.22","4.3.21","4.3.20","4.3.19","4.3.18","4.3.17","4.3.16","4.3.15","4.3.14","4.3.13","4.3.12","4.3.11","4.3.10","4.3.9","4.3.8","4.3.7","4.3.5","4.3.4","4.3.3","4.3.2","4.3.1","4.3.0","4.2.14","4.2.13","4.2.12","4.2.11","4.2.10","4.2.9","4.2.8","4.2.7","4.2.6","4.2.5","4.2.4","4.2.3","4.2.2","4.2.1","4.2.0","4.1.29","4.1.28","3.6.18","3.6.17","3.6.16","3.6.15","3.6.5","3.6.0.1","3.5.9","3.5.7","3.5.5","3.5.1","3.5.0","3.4.3.6","3.4.0","3.3.9.4","3.3.8","3.3.6","3.5.5.10","3.3.4","3.3.3","3.3.1.1","3.3.0","3.2.9.13","3.2.9","3.2.8","3.2.6","3.2.5","3.2.4","3.2.3","3.2.2","3.2.1","3.1.9","3.1.8","3.1.6","3.1.4","3.1.3","3.1.2","3.1.0","3.0.9","3.0.8","3.0.7","3.0.6","3.0.5","3.0.4","3.0.0-beta"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88999.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"}]}