CVE-2026-90992

CVE-2026-90992 published: The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User Meta Merge via 'user-mediaurl' Media Field in all versions up to, and including, 4.5.14 due to insufficient input sanitization and output escaping. This makes it ...

View full NVD advisory → ← Back to CVE watch