Impact
A stored cross‑site scripting flaw exists in Greenshift – animation and page builder blocks when using the customapi action handler in versions up to and including 12.8.9. The plugin fails to sanitise API responses before inserting them into the page via innerHTML, allowing an attacker with contributor‑level access or higher to persistently inject malicious JavaScript into a page. When any site visitor loads the affected page, the injected script runs in the visitor’s browser, enabling credential theft, session hijacking, and other client‑side compromise activities.
Affected Systems
All WordPress sites that have the Greenshift plugin installed in any release whose version number is 12.8.9 or older are affected. The vulnerability resides solely in the plugin’s API handling code and applies to any user that can access the customapi action as a contributor or higher.
Risk and Exploitability
The technical severity is set to a CVSS score of 6.4, indicating moderate risk. Because the exploit requires authenticated access, an attacker must first obtain Contributor or higher privileges on the target WordPress installation. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it is not among the most widely exploited flaws. Nonetheless, the stored payload persists in the database, meaning any future visitor to the affected page will be exposed to the injected script until the issue is fixed or mitigated.
OpenCVE Enrichment