davidanderson Vulnerabilities and Affected Products
Vulnerabilities associated with Redux Framework.
Products
Clear product- UpdraftPlus: WP Backup & Migration Plugin4 vulnerabilities
- Internal Link Juicer: SEO Auto Linker for WordPress3 vulnerabilities
- All-In-One Security (AIOS) – Security and Firewall2 vulnerabilities
- Redux Framework2 vulnerabilities
- WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance2 vulnerabilities
- Easy Updates Manager1 vulnerability
- Testimonial Slider1 vulnerability
- WPGet API – Connect to any external REST API1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-9488MEDIUM | Redux Framework <= 4.5.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via data ParameterThe Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data’ parameter in all versions up to, and including, 4.5.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CWE-79Dec 13, 2025 | CVSS6.4v3.1 | EPSS0.292% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-6828HIGH | Redux Framework 4.4.12 - 4.4.17 - Unauthenticated JSON File Upload to Stored Cross-Site ScriptingThe Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization and capability checks on the Redux_Color_Scheme_Import function in versions 4.4.12 to 4.4.17. This makes it possible for unauthenticated attackers to upload JSON files, which can be used to conduct stored cross-site scripting attacks and, in some rare cases, when the wp_filesystem fails to initialize - to Remote Code Execution. CWE-434Jul 23, 2024 | CVSS7.2v3.1 | EPSS1.03% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |