Redux's vulnerability footprint centers on its WordPress template and framework products, with the recurring signal dominated by information-disclosure and access-control weaknesses including exposure of sensitive data, improper privilege handling, incorrect authorization, and weak credential-storage practices. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Redux over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-38314MEDIUM The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions available to unauthenticated users in the `includes` function in `re | Sep 2, 2021 | 5.3 | 45 | NO | YES |
CVE-2021-38312MEDIUM The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress used an incorrect authorization check in the REST API endpoints registered under the “redux/v1/templ | Sep 2, 2021 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Redux.
Media articles that mention a CVE ID that affects a product developed by Redux — matched by CVE ID, not by vendor name.