PT-2026-79553 · WordPress · Greenshift – Animation/Page Builder Blocks

CVE-2026-5093

·

Published

2026-08-22

·

Updated

2026-08-24

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions GreenShift – Animation and Page Builder Blocks versions prior to 12.9.0
Description The GreenShift – Animation and Page Builder Blocks plugin for WordPress allows unauthorized modification of data. The issue stems from a missing capability check in the gspb update global wp settings() function, which only verifies the edit posts capability rather than requiring administrative privileges. Consequently, authenticated users with contributor-level access or higher can modify global WordPress theme color settings across the entire site, which may result in site defacement.
Recommendations Update the plugin to a version newer than 12.8.9. As a temporary mitigation, restrict user roles from having the edit posts capability if they are not trusted administrators.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5093

Affected Products

Greenshift – Animation/Page Builder Blocks