WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Redux Framework?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Redux Framework — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: redux-framework
  • 900000+ instalaciones activas

adminoptionsoptions frameworkplugin optionstheme options

Estado de mantenimiento

  • Última versión conocida: 4.5.13
  • Requiere PHP: 7.4+
  • PHP máximo soportado (analizado): 8.4

Vulnerabilidades conocidas

4 CVEs conocidos registrados para Redux Framework.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-12525 Redux Framework [redux-framework] < 4.5.13 Gestión incorrecta de privilegios Desconocido < 4.5.13 4.5.13 2026-07-16 ✓ corregido en la última versión
CVE-2024-6828 Redux Framework [redux-framework] < 4.4.18 Carga de archivos sin restricción de tipo peligroso Alta 7,2 < 4.4.18 4.4.18 2024-07-22 ✓ corregido en la última versión
CVE-2021-38312 Redux Framework [redux-framework] < 4.2.13 Manejo incorrecto de permisos o privilegios insuficientes Media 6,5 < 4.2.13 4.2.13 2021-09-01 ✓ corregido en la última versión
CVE-2021-38314 Redux Framework [redux-framework] < 4.2.13 Exposición de información sensible a un actor no autorizado Media 5,3 < 4.2.13 4.2.13 2021-09-01 ✓ corregido en la última versión
Redux Framework [redux-framework] < 4.1.21 Desconocido < 4.1.21 4.1.21 2020-12-15 ✓ corregido en la última versión
Redux Framework [redux-framework] >= 4.1.22 - <= 4.1.23 Desconocido 4.1.22–4.1.23 4.1.23 2020-12-15 ✓ corregido en la última versión
Redux Framework [redux-framework] < 4.1.21 Desconocido < 4.1.21 4.1.21 2020-12-15 ✓ corregido en la última versión
Redux Framework [redux-framework] < 4.1.24 Desconocido < 4.1.24 4.1.24 2020-12-15 ✓ corregido en la última versión

CVE-2026-12525

The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing users with at least the Subscriber role to escalate their privileges to Administrator by submitting a crafted value while updating their own profile, on sites where the Redux Framework WordPress plugin before 4.5.13's user-profile (Users extension) feature is enabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-6828

The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization and capability checks on the Redux_Color_Scheme_Import function in versions 4.4.12 to 4.4.17. This makes it possible for unauthenticated attackers to upload JSON files, which can be used to conduct stored cross-site scripting attacks and, in some rare cases, when the wp_filesystem fails to initialize - to Remote Code Execution.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2021-38312

The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress used an incorrect authorization check in the REST API endpoints registered under the “redux/v1/templates/” REST Route in “redux-templates/classes/class-api.php”. The `permissions_callback` used in this file only checked for the `edit_posts` capability which is granted to lower-privileged users such as contributors, allowing such users to install arbitrary plugins from the WordPress repository and edit arbitrary posts.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2021-38314

The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions available to unauthenticated users in the `includes` function in `redux-core/class-redux-core.php` that were unique to a given site but deterministic and predictable given that they were based on an md5 hash of the site URL with a known salt value of '-redux' and an md5 hash of the previous hash with a known salt value of '-support'. These AJAX actions could be used to retrieve a list of active plugins and their versions, the site's PHP version, and an unsalted md5 hash of site’s `AUTH_KEY` concatenated with the `SECURE_AUTH_KEY`.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Redux Framework [redux-framework] < 4.1.21

Cross-Site Request Forgery (CSRF) Nonce Validation Bypass vulnerability found by Lenon Leite (DevSoftIn) in WordPress Redux plugin (versions <= 4.1.20).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Redux Framework [redux-framework] >= 4.1.22 - <= 4.1.23

Cross-Site Request Forgery (CSRF) Nonce Validation Bypass vulnerability found by ErwanLR in WordPress Redux Framework (versions 4.1.22 - 4.1.23).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Redux Framework [redux-framework] < 4.1.21

CSRF Nonce Validation Bypass vulnerability discovered by Lenon Leite in WordPress Redux Framework plugin (versions <= 4.1.20).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Redux Framework [redux-framework] < 4.1.24

The Gutenberg Template Library & Redux Framework plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.23. This is due to incorrect nonce validation in the 'Redux AJAX Save' class. This makes it possible for unauthenticated attackers to update the plugin's settings granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

+ 4 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
Redux Framework [redux-framework] < 4.1.21 Desconocido < 4.1.21 4.1.21 2020-11-23 ✓ corregido en la última versión
Redux Framework [redux-framework] < 4.5.9 Media 6,4 < 4.5.9 4.5.9 0000-00-00 ✓ corregido en la última versión
Redux Framework [redux-framework] < 4.1.21 Desconocido < 4.1.21 4.1.21 ✓ corregido en la última versión
Redux Framework [redux-framework] < 4.1.24 Desconocido < 4.1.24 4.1.24 ✓ corregido en la última versión

Redux Framework [redux-framework] < 4.1.21

The Gutenberg Template and Pattern Library & Redux Framework plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.20. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to modify settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Redux Framework [redux-framework] < 4.5.9

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data’ parameter in all versions up to, and including, 4.5.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Redux Framework [redux-framework] < 4.1.21

The plugin did not properly validate some nonces, only checking them if their value was set. As a result, CSRF attacks could still be performed by not submitting the nonce in the request, bypassing the protection they are supposed to provide.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Redux Framework [redux-framework] < 4.1.24

The plugin re-introduced a CSRF bypass issue in v4.1.22, as the nonce is only checked if present in the request.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Mantén Redux Framework actualizado — 4.5.13 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

  • CMB2 — 300000+ instalaciones activas — 100/100 (91) — PHP máx. 8.4
  • OptionTree — 50000+ instalaciones activas — 94/100 (105) — PHP máx. 8.4
  • ACF Options For Polylang — 10000+ instalaciones activas — 88/100 (17) — PHP máx. 8.4
  • Options Framework — 10000+ instalaciones activas — 96/100 (27)
  • AAA Option Optimizer — 9000+ instalaciones activas — 92/100 (25)

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.