CVE-2026-5410

CVE-2026-5410 published: The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the spinner field in versions up to, and including, 4.5.13 This is due to insufficient input sanitization and output escaping. In the user_meta_save() function scalar ...

View full NVD advisory → ← Back to CVE watch