Impact
The Greenshift plugin for WordPress fails to properly neutralize input that is later rendered as part of a web page, allowing attackers to embed malicious JavaScript that is stored in the site’s content. When visitors load the affected page, the malicious script runs in their browsers, potentially stealing session cookies, defacing the site, or redirecting users to attacker‑controlled sites.
Affected Systems
WordPress installations using the Greenshift animation and page builder block plugin version 10.8 or earlier are affected. This applies to all releases of the plugin from its first version up to and including 10.8, distributed by wpsoul.
Risk and Exploitability
The CVSS score is 6.5, indicating a medium severity. The EPSS score of less than 1% suggests a low probability of exploitation today, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be stored XSS through content created or edited via the plugin’s interface, where an attacker can inject a script that is then served to all site visitors.
OpenCVE Enrichment
EUVD