Junglewise Threat Intelligence

CVE-2026-5410: Redux Framework plugin WordPress stored XSS in spinner field

CVE-2026-5410 · Severity: medium · CVSS 6.4 · Published 2026-09-19

Executive brief

The Redux Framework WordPress plugin allows authenticated users with subscriber access or higher to inject malicious scripts into pages through a spinner form field. When other users view pages containing the injected content, the scripts execute in their browsers, potentially allowing attackers to steal credentials, hijack sessions, or deface content. This vulnerability affects versions up to 4.5.13 and requires an authenticated attacker.

Technical details

The vulnerability exists in the user_meta_save() and render() functions where scalar spinner field values bypass array-only sanitization logic and are later rendered in unquoted HTML attributes without escaping. An authenticated attacker with subscriber-level access can inject arbitrary JavaScript through the spinner field, which persists in user meta and executes when the page is viewed by other users. A patch is available in versions after 4.5.13.

Affected products

  • Redux Redux Framework up to and including 4.5.13

Timeline

  • 2026-09-19: disclosed: CVE-2026-5410 published on NVD

References