PT-2026-79553 · WordPress · Greenshift – Animation/Page Builder Blocks
CVE-2026-5093
·
Published
2026-08-22
·
Updated
2026-08-24
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GreenShift – Animation and Page Builder Blocks versions prior to 12.9.0
Description
The GreenShift – Animation and Page Builder Blocks plugin for WordPress allows unauthorized modification of data. The issue stems from a missing capability check in the
gspb update global wp settings() function, which only verifies the edit posts capability rather than requiring administrative privileges. Consequently, authenticated users with contributor-level access or higher can modify global WordPress theme color settings across the entire site, which may result in site defacement.Recommendations
Update the plugin to a version newer than 12.8.9.
As a temporary mitigation, restrict user roles from having the
edit posts capability if they are not trusted administrators.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Greenshift – Animation/Page Builder Blocks