Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Redux Framework — verificado contra la base de datos de seguridad local de WP Clinic.
Qué hace este plugin
- Slug:
redux-framework
- 900000+ instalaciones activas
adminoptionsoptions frameworkplugin optionstheme options
Estado de mantenimiento
- Última versión conocida: 4.5.13
- Requiere PHP: 7.4+
- PHP máximo soportado (analizado): 8.4
Vulnerabilidades conocidas
4 CVEs conocidos registrados para Redux Framework.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2026-12525
|
Redux Framework [redux-framework] < 4.5.13 |
Gestión incorrecta de privilegios |
Desconocido
|
< 4.5.13
|
4.5.13 |
2026-07-16 |
✓ corregido en la última versión
|
|
CVE-2024-6828
|
Redux Framework [redux-framework] < 4.4.18 |
Carga de archivos sin restricción de tipo peligroso |
Alta
7,2
|
< 4.4.18
|
4.4.18 |
2024-07-22 |
✓ corregido en la última versión
|
|
CVE-2021-38312
|
Redux Framework [redux-framework] < 4.2.13 |
Manejo incorrecto de permisos o privilegios insuficientes |
Media
6,5
|
< 4.2.13
|
4.2.13 |
2021-09-01 |
✓ corregido en la última versión
|
|
CVE-2021-38314
|
Redux Framework [redux-framework] < 4.2.13 |
Exposición de información sensible a un actor no autorizado |
Media
5,3
|
< 4.2.13
|
4.2.13 |
2021-09-01 |
✓ corregido en la última versión
|
|
—
|
Redux Framework [redux-framework] < 4.1.21 |
— |
Desconocido
|
< 4.1.21
|
4.1.21 |
2020-12-15 |
✓ corregido en la última versión
|
|
—
|
Redux Framework [redux-framework] >= 4.1.22 - <= 4.1.23 |
— |
Desconocido
|
4.1.22–4.1.23
|
4.1.23 |
2020-12-15 |
✓ corregido en la última versión
|
|
—
|
Redux Framework [redux-framework] < 4.1.21 |
— |
Desconocido
|
< 4.1.21
|
4.1.21 |
2020-12-15 |
✓ corregido en la última versión
|
|
—
|
Redux Framework [redux-framework] < 4.1.24 |
— |
Desconocido
|
< 4.1.24
|
4.1.24 |
2020-12-15 |
✓ corregido en la última versión
|
CVE-2026-12525
The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing users with at least the Subscriber role to escalate their privileges to Administrator by submitting a crafted value while updating their own profile, on sites where the Redux Framework WordPress plugin before 4.5.13's user-profile (Users extension) feature is enabled.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-6828
The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization and capability checks on the Redux_Color_Scheme_Import function in versions 4.4.12 to 4.4.17. This makes it possible for unauthenticated attackers to upload JSON files, which can be used to conduct stored cross-site scripting attacks and, in some rare cases, when the wp_filesystem fails to initialize - to Remote Code Execution.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2021-38312
The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress used an incorrect authorization check in the REST API endpoints registered under the “redux/v1/templates/” REST Route in “redux-templates/classes/class-api.php”. The `permissions_callback` used in this file only checked for the `edit_posts` capability which is granted to lower-privileged users such as contributors, allowing such users to install arbitrary plugins from the WordPress repository and edit arbitrary posts.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2021-38314
The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions available to unauthenticated users in the `includes` function in `redux-core/class-redux-core.php` that were unique to a given site but deterministic and predictable given that they were based on an md5 hash of the site URL with a known salt value of '-redux' and an md5 hash of the previous hash with a known salt value of '-support'. These AJAX actions could be used to retrieve a list of active plugins and their versions, the site's PHP version, and an unsalted md5 hash of site’s `AUTH_KEY` concatenated with the `SECURE_AUTH_KEY`.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
Redux Framework [redux-framework] < 4.1.21
Cross-Site Request Forgery (CSRF) Nonce Validation Bypass vulnerability found by Lenon Leite (DevSoftIn) in WordPress Redux plugin (versions <= 4.1.20).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Redux Framework [redux-framework] >= 4.1.22 - <= 4.1.23
Cross-Site Request Forgery (CSRF) Nonce Validation Bypass vulnerability found by ErwanLR in WordPress Redux Framework (versions 4.1.22 - 4.1.23).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Redux Framework [redux-framework] < 4.1.21
CSRF Nonce Validation Bypass vulnerability discovered by Lenon Leite in WordPress Redux Framework plugin (versions <= 4.1.20).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Redux Framework [redux-framework] < 4.1.24
The Gutenberg Template Library & Redux Framework plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.23. This is due to incorrect nonce validation in the 'Redux AJAX Save' class. This makes it possible for unauthenticated attackers to update the plugin's settings granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
+ 4 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
—
|
Redux Framework [redux-framework] < 4.1.21 |
— |
Desconocido
|
< 4.1.21
|
4.1.21 |
2020-11-23 |
✓ corregido en la última versión
|
|
—
|
Redux Framework [redux-framework] < 4.5.9 |
— |
Media
6,4
|
< 4.5.9
|
4.5.9 |
0000-00-00 |
✓ corregido en la última versión
|
|
—
|
Redux Framework [redux-framework] < 4.1.21 |
— |
Desconocido
|
< 4.1.21
|
4.1.21 |
— |
✓ corregido en la última versión
|
|
—
|
Redux Framework [redux-framework] < 4.1.24 |
— |
Desconocido
|
< 4.1.24
|
4.1.24 |
— |
✓ corregido en la última versión
|
Redux Framework [redux-framework] < 4.1.21
The Gutenberg Template and Pattern Library & Redux Framework plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.20. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to modify settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Redux Framework [redux-framework] < 4.5.9
The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data’ parameter in all versions up to, and including, 4.5.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
Redux Framework [redux-framework] < 4.1.21
The plugin did not properly validate some nonces, only checking them if their value was set. As a result, CSRF attacks could still be performed by not submitting the nonce in the request, bypassing the protection they are supposed to provide.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Redux Framework [redux-framework] < 4.1.24
The plugin re-introduced a CSRF bypass issue in v4.1.22, as the nonce is only checked if present in the request.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Cómo solucionarlo
Mantén Redux Framework actualizado — 4.5.13 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Alternativas más seguras / más establecidas