Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Greenshift – animation and page builder blocks — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in Greenshift – animation and page builder blocks, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security weaknesses related to the Greenshift – animation and page builder blocks WordPress plugin, categorized under common vulnerability classifications such as cross-site scripting or insecure default configurations. It serves as a centralized repository for tracking security issues identified within this specific third-party extension, providing context for developers and site administrators who rely on its features for building dynamic web content. The collection encompasses reports and advisories issued over a broad historical time range, capturing both recently disclosed issues and older vulnerabilities that may still impact legacy installations. Readers can utilize this resource to monitor vendor-specific security advisories, gaining insight into how quickly issues are addressed and patched by the Greenshift development team. By examining the details here, users can better understand the nature of prevalent weakness classes affecting this plugin, such as input validation failures or improper access controls, and assess the potential risks to their own websites. Furthermore, this page allows for a comprehensive look up of a product's vulnerability history, enabling security researchers and IT professionals to analyze trends, compare severity levels, and review remediation efforts over time. This aggregated data supports informed decision-making regarding plugin updates, security audits, and the overall hygiene of WordPress environments, ensuring that users are aware of the specific threats associated with Greenshift and can take appropriate mitigation steps to protect their digital assets from exploitation.

Vendor: Wpsoul

CVE ID Title CVSS Severity Published
CVE-2026-93880 Greenshift <= 13.2.0 - Reflected Cross-Site Scripting via '{{GET:}}' Dynamic Placeholder CWE-79 6.1 Medium 2026-10-02
CVE-2026-5092 Greenshift <= 12.8.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Data URI CWE-79 6.4 Medium 2026-08-26
CVE-2026-5093 Greenshift <= 12.8.9 - Authenticated (Contributor+) Theme Settings Modification via 'gspb_update_global_wp_settings' CWE-862 4.3 Medium 2026-08-22
CVE-2026-4895 Greenshift <= 12.8.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via disablelazy Attribute CWE-79 6.4 Medium 2026-04-11
CVE-2026-2371 Greenshift <= 12.8.3 - Missing Authorization to Unauthenticated Private Reusable Block Disclosure via 'gspb_el_reusable_load' CWE-862 5.3 Medium 2026-03-06
CVE-2026-2589 Greenshift – animation and page builder blocks <= 12.8.3 - Unauthenticated Sensitive Information Exposure via Settings Backup CWE-200 5.3 Medium 2026-03-05
CVE-2026-2593 Greenshift – animation and page builder blocks <= 12.8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium 2026-03-05
CVE-2026-1927 GreenShift - Animation and Page Builder Blocks <= 12.6 - Missing Authorization to Authenticated (Subscriber+) Information Disclosure of AI API Keys and Stored Cross-Site Scripting via custom_css CWE-862 5.4 Medium 2026-02-05
CVE-2025-11841 Greenshift – animation and page builder blocks <= 12.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Chart Data Attributes CWE-79 6.4 Medium 2025-11-04
CVE-2025-3616 Greenshift 11.4 - 11.4.5 - Authenticated (Subscriber+) Arbitrary File Upload CWE-434 8.8 High 2025-04-22
CVE-2024-6155 Greenshift – animation and page builder blocks <= 9.0.0 - Missing Authorization to Authenticated (Subscriber+) Server-Side Request Forgery and Stored Cross-Site Scripting CWE-862 6.4 Medium 2025-01-09
CVE-2024-11181 Greenshift – animation and page builder blocks <= 9.9.9.3 - Authenticated (Contributor+) Post Disclosure CWE-639 4.3 Medium 2024-12-12
CVE-2024-35765 WordPress Greenshift – animation and page builder blocks plugin <= 8.8.9.1 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2024-06-19
CVE-2023-6636 Greenshift – animation and page builder blocks <= 7.6.2 - Authenticated (Administrator+) Arbitrary File Upload CWE-434 7.2 High 2024-01-11
CVE-2023-22707 WordPress Greenshift – animation and page builder blocks Plugin <= 4.9.9 is vulnerable to Cross Site Scripting (XSS) CWE-79 5.9 Medium 2023-03-27

All 15 known CVE vulnerabilities affecting Greenshift – animation and page builder blocks with full Chinese analysis, references, and POCs where available.