That was three years ago! If you’d bothered to do any further research before posting this, you’d know that this problem has long since been fixed.
This plugin has been invaluable for me, although stick with 3.9.5 for now – 3.9.6+ has significant code changes which have resulted in a lot of bugs, but no XSS injections!
Plugin Author
radiok
(@radiok)
I’ll have to second what ljmac said, for one thing, that post is in regard to Register Plus (non-Redux), the plugin from which Redux was forked. However, I did inherit many issues from the plugin which have been resolved in the 3.9 branch. Do you have any specific concerns or are you just trying to raise awareness?