CVE-2026-90992 | davidanderson Redux Framework Plugin up to 4.5.14 on WordPress Media Field user-mediaurl cross site scripting

SecurityVulns

A vulnerability classified as problematic was found in davidanderson Redux Framework Plugin up to 4.5.14 on WordPress. Impacted is an unknown function of the component Media Field. Such manipulation of the argument user-mediaurl leads to cross site scripting.

This vulnerability is listed as CVE-2026-90992. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More