WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Redux Framework

Redux is a simple, truly extensible, and fully responsive options framework for WordPress themes and plugins. It ships with an integrated demo.

7Reported vulnerabilities
8.8Highest CVSS score
4.5.13Latest version
900,000+Active installs

What to do now

Update Redux Framework to 4.5.13 or later. 7 of these have a fixed version available. Updating resolves them.

Plugin last updated: June 22, 2026 / Tested up to WordPress: 7.1 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2021-38314 Medium 5.3 29.0% 4.2.11 and earlier 4.2.13 September 2, 2021
CVE-2021-38312 Medium 6.5 1.3% 4.2.11 and earlier 4.2.13 September 2, 2021
CVE-2026-12525 High 8.8 0.2% 4.5.12 and earlier 4.5.13 June 25, 2026
WF-07422361-3c7c-4e3c-bbfb-097c7fe5f2b4 High 8.8 4.1.20 and earlier 4.1.21 November 23, 2020
CVE-2024-6828 High 7.2 1.0% 4.4.12 to 4.4.17 (inclusive)
4.4.12 to 4.4.17 (inclusive)
4.4.18 July 23, 2024
CVE-2025-9488 Medium 6.4 0.3% 0 to 4.5.8 (inclusive) 4.5.9 December 13, 2025
WF-adebcf1c-bb22-4a25-b79b-b76eb3b3023f Medium 5.3 Before 4.1.24 4.1.24 December 15, 2020

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.