Impact
Improper neutralization of input during web page generation in the Greenshift animation and page‑builder blocks plugin permits a DOM‑based cross‑site scripting flaw (CWE‑79). This vulnerability allows the execution of arbitrary JavaScript in the context of a user’s browser when the plugin renders content.
Affected Systems
WordPress sites that use the Greenshift plugin version 11.5.5 or earlier are affected. The vulnerability applies to all releases from the earliest build through and including 11.5.5.
Risk and Exploitability
The CVSS rating of 6.5 indicates moderate severity, and the EPSS score of less than 1 % signifies a low probability of exploitation. The vulnerability is not listed in CISA KEV. It is inferred that the attack vector is client‑side, where an attacker can supply crafted content that is rendered by the plugin, triggering the DOM‑based XSS; no server‑side privileges are required.
OpenCVE Enrichment
EUVD