CVE-2021-38314Patch(redux / gutenberg_template_library_\&_redux_framework)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch redux gutenberg_template_library_\&_redux_framework systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions available to unauthenticated users in the `includes` function in `redux-core/class-redux-core.php` that were unique to a given site but deterministic and predictable given that they were based on an md5 hash of the site URL with a known salt value of '-redux' and an md5 hash of the previous hash with a known salt value of '-support'. These AJAX actions could be used to retrieve a list of active plugins and their versions, the site's PHP version, and an unsalted md5 hash of site’s `AUTH_KEY` concatenated with the `SECURE_AUTH_KEY`.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-760CWE-916

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gutenberg_template_library_\&_redux_framework

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
gutenberg_template_library_\&_redux_framework

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-24: 1Patch / Workaround · 2026-05-24: 1Technical Details · 2026-05-24: 105-24
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Stephane Jourdan@sjourdan
    Patch

    Inherited a WP site on an abandoned ThemeForest theme bundling Redux Framework from 2017. Used Opus to audit it: 5 critical findings incl CVE-2021-38314. Leaks some key hashes to any anonymous visitor. CC wrote a 175-line mu-plugin and now all 9 endpoints return 403. Amazing

    Post summary

    The post reports a critical CVE (2021‑38314) found in an abandoned WordPress theme and notes that a custom mu‑plugin was created to mitigate the flaw, preventing endpoint access. No exploitation or PoC details are included.

    0000095
    557 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appreduxgutenberg_template_library_\&_redux_framework-wordpress-

Explore more