PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-88999 davidanderson CVE debrief

The Redux Framework plugin for WordPress has an authorization bypass vulnerability in all versions up to and including 4.5.14. This allows authenticated attackers with subscriber-level access and above to delete arbitrary media library attachments, including administrator-owned files. The vulnerability arises from improper authorization checks, enabling subscribers to exploit this issue when a Custom Fonts field is registered on the user profile page. Defenders should verify exposure, apply patches, and restrict access to media library attachments for low-privileged users. This vulnerability could lead to potential unauthorized deletion of media library attachments, possible site

Vendor
davidanderson
Product
Redux Framework
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-01
Original CVE updated
2026-10-03
Advisory published
2026-10-01
Advisory updated
2026-10-03

Who should care

Defenders responsible for WordPress sites using the Redux Framework plugin should assess exposure and apply patches. Site administrators and security teams should verify the version of the plugin and restrict access to media library attachments for low-privileged users.

Why it matters

The Redux Framework plugin for WordPress has an authorization bypass vulnerability allowing subscribers to delete arbitrary media library attachments. Defenders should verify exposure, apply patches, and restrict access to media library attachments for low-privileged users.

  • Potential unauthorized deletion of media library attachments
  • Possible disruption to site content and functionality
  • Need for verification of plugin version and exposure
  • Priority for applying patches or mitigations

Technical summary

The Redux Framework plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.14. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary media library attachments, including administrator-owned files, from the affected site.

Defensive priority

Defenders should prioritize verifying exposure and applying patches due to the potential for unauthorized media deletion.

Recommended defensive actions

  • Verify the version of Redux Framework plugin and update to a patched version if necessary
  • Restrict access to media library attachments for subscribers and other low-privileged users
  • Monitor for unauthorized media deletions
  • Implement additional logging and monitoring for media library access
  • Conduct regular security audits to identify potential vulnerabilities
  • Review and update incident response plans to address potential exploitation
  • Ensure that all users with access to the media library have the appropriate permissions

Evidence notes

The vulnerability is due to improper authorization checks in the Redux Framework plugin. An attacker with subscriber-level access can delete media library attachments by exploiting this issue when a Custom Fonts field is registered on the user profile page.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-88999 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-88999

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-88999 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-88999

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/reduxframework/redux-framework/pull/4117/changes

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.5.13/redux-core/inc/extensions/custom_fonts/class-redux-extension-custom-fonts.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.5.13/redux-core/inc/extensions/custom_fonts/custom_fonts/class-redux-custom-fonts.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.5.14/redux-core/inc/extensions/custom_fonts/class-redux-extension-custom-fonts.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.5.14/redux-core/inc/extensions/custom_fonts/custom_fonts/class-redux-custom-fonts.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/changeset/3705066/redux-framework/trunk/redux-core/inc/extensions/custom_fonts/class-redux-extension-custom-fonts.php

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.