PatchSiren cyber security CVE debrief
CVE-2026-88999 davidanderson CVE debrief
The Redux Framework plugin for WordPress has an authorization bypass vulnerability in all versions up to and including 4.5.14. This allows authenticated attackers with subscriber-level access and above to delete arbitrary media library attachments, including administrator-owned files. The vulnerability arises from improper authorization checks, enabling subscribers to exploit this issue when a Custom Fonts field is registered on the user profile page. Defenders should verify exposure, apply patches, and restrict access to media library attachments for low-privileged users. This vulnerability could lead to potential unauthorized deletion of media library attachments, possible site
- Vendor
- davidanderson
- Product
- Redux Framework
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-01
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-10-01
- Advisory updated
- 2026-10-03
Who should care
Defenders responsible for WordPress sites using the Redux Framework plugin should assess exposure and apply patches. Site administrators and security teams should verify the version of the plugin and restrict access to media library attachments for low-privileged users.
Why it matters
The Redux Framework plugin for WordPress has an authorization bypass vulnerability allowing subscribers to delete arbitrary media library attachments. Defenders should verify exposure, apply patches, and restrict access to media library attachments for low-privileged users.
- Potential unauthorized deletion of media library attachments
- Possible disruption to site content and functionality
- Need for verification of plugin version and exposure
- Priority for applying patches or mitigations
Technical summary
The Redux Framework plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.14. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary media library attachments, including administrator-owned files, from the affected site.
Defensive priority
Defenders should prioritize verifying exposure and applying patches due to the potential for unauthorized media deletion.
Recommended defensive actions
- Verify the version of Redux Framework plugin and update to a patched version if necessary
- Restrict access to media library attachments for subscribers and other low-privileged users
- Monitor for unauthorized media deletions
- Implement additional logging and monitoring for media library access
- Conduct regular security audits to identify potential vulnerabilities
- Review and update incident response plans to address potential exploitation
- Ensure that all users with access to the media library have the appropriate permissions
Evidence notes
The vulnerability is due to improper authorization checks in the Redux Framework plugin. An attacker with subscriber-level access can delete media library attachments by exploiting this issue when a Custom Fonts field is registered on the user profile page.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-88999 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-88999
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-88999 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-88999
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/reduxframework/redux-framework/pull/4117/changes
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.5.13/redux-core/inc/extensions/custom_fonts/class-redux-extension-custom-fonts.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.5.13/redux-core/inc/extensions/custom_fonts/custom_fonts/class-redux-custom-fonts.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.5.14/redux-core/inc/extensions/custom_fonts/class-redux-extension-custom-fonts.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.5.14/redux-core/inc/extensions/custom_fonts/custom_fonts/class-redux-custom-fonts.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/changeset/3705066/redux-framework/trunk/redux-core/inc/extensions/custom_fonts/class-redux-extension-custom-fonts.php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.