PLUGIN SECURITY
Is Redux Framework safe?
Redux is a simple, truly extensible, and fully responsive options framework for WordPress themes and plugins. It ships with an integrated demo.
What this plugin does
- Slug:
redux-framework - Author: David Anderson / Team Updraft
- 900000+ active installs
- 88/100 rating (273 reviews on wordpress.org)
- 32624427 all-time downloads
- On WordPress.org since 2013-10-24
adminoptionsoptions frameworkplugin optionstheme options
Maintenance status
- Latest known version: 4.5.13
- Last updated: 2026-06-22 6:40pm GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
5 known CVEs on file for Redux Framework.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-12525 | Redux Framework [redux-framework] < 4.5.13 | Improper Privilege Management | Unknown | < 4.5.13 | 4.5.13 | 2026-06-25 | ✓ fixed in latest |
| CVE-2024-6828 | Redux Framework [redux-framework] < 4.4.18 | Unrestricted Upload of File with Dangerous Type | High 7.2 | < 4.4.18 | 4.4.18 | 2024-07-22 | ✓ fixed in latest |
| CVE-2021-38312 | Redux Framework [redux-framework] < 4.2.13 | Improper Handling of Insufficient Permissions or Privileges | Medium 6.5 | < 4.2.13 | 4.2.13 | 2021-09-01 | ✓ fixed in latest |
| CVE-2021-38314 | Redux Framework [redux-framework] < 4.2.13 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 5.3 | < 4.2.13 | 4.2.13 | 2021-09-01 | ✓ fixed in latest |
| — | Redux Framework [redux-framework] < 4.1.21 | — | Unknown | < 4.1.21 | 4.1.21 | 2020-12-15 | ✓ fixed in latest |
| — | Redux Framework [redux-framework] >= 4.1.22 - <= 4.1.23 | — | Unknown | 4.1.22–4.1.23 | 4.1.23 | 2020-12-15 | ✓ fixed in latest |
| — | Redux Framework [redux-framework] < 4.1.21 | — | Unknown | < 4.1.21 | 4.1.21 | 2020-12-15 | ✓ fixed in latest |
| — | Redux Framework [redux-framework] < 4.1.24 | — | Unknown | < 4.1.24 | 4.1.24 | 2020-12-15 | ✓ fixed in latest |
+ 7 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| — | Redux Framework [redux-framework] < 4.1.21 | — | Unknown | < 4.1.21 | 4.1.21 | 2020-11-23 | ✓ fixed in latest |
| — | Redux Framework [redux-framework] < 4.5.9 | — | Medium 6.4 | < 4.5.9 | 4.5.9 | 0000-00-00 | ✓ fixed in latest |
| — | Redux Framework [redux-framework] < 4.1.21 | — | Unknown | < 4.1.21 | 4.1.21 | — | ✓ fixed in latest |
| — | Redux Framework [redux-framework] < 4.1.24 | — | Unknown | < 4.1.24 | 4.1.24 | — | ✓ fixed in latest |
| — | Redux Framework < 4.1.21 - CSRF Nonce Validation Bypass | — | Unknown | < 4.1.21 | 4.1.21 | — | ✓ fixed in latest |
| — | Redux Framework 4.1.22 - 4.1.23 - CSRF Nonce Validation Bypass | — | Unknown | < 4.1.24 | 4.1.24 | — | ✓ fixed in latest |
| CVE-2025-9488 | Redux Framework < 4.5.9 - Contributor+ Stored XSS via data Parameter | — | Unknown | < 4.5.9 | 4.5.9 | — | ✓ fixed in latest |
How to fix it
Keep Redux Framework updated — 4.5.13 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- CMB2 — 300000+ active installs — 100/100 (91) — max PHP 8.4
- OptionTree — 50000+ active installs — 94/100 (105) — max PHP 8.4
- ACF Options For Polylang — 20000+ active installs — 88/100 (17) — max PHP 8.4
- Options Framework — 10000+ active installs — 96/100 (27)
- AAA Option Optimizer — 9000+ active installs — 92/100 (25)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.