Description
The GreenShift – Animation and Page Builder Blocks plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 12.8.9. This is due to a missing capability check on the 'gspb_update_global_wp_settings' function that only verifies the 'edit_posts' capability instead of requiring administrative privileges. This makes it possible for authenticated attackers, with contributor-level access and above, to modify global WordPress theme color settings site-wide, leading to site defacement.
Published: 2026-08-22
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability occurs in the Greenshift WordPress plugin due to a missing capability check on the gspb_update_global_wp_settings function. This check only verifies that the user has the "edit_posts" capability instead of requiring higher administrative privileges. As a result, any authenticated user with contributor-level access and higher can modify global WordPress theme color settings site‑wide, which can lead to defacement of the site. The weakness is a missing authorization check (CWE‑862).

Affected Systems

The affected product is the Greenshift – animation and page builder blocks plugin from wpsoul. Versions up to and including 12.8.9 are vulnerable. Users running any of those releases should verify their installation version.

Risk and Exploitability

The CVSS score of 4.3 indicates a low to medium severity vulnerability. No EPSS value is available, and the vulnerability is not listed in CISA KEV, suggesting that exploitation is unlikely in the wild. The attack vector requires an authenticated user with at least contributor privileges, which may be present on many sites. While the impact is limited to cosmetic defacement rather than data loss or remote code execution, it can damage brand trust and site integrity. Overall, the risk is moderate for sites where contributors have ubiquitous access and the plugin’s theme settings are visible to visitors.

Generated by OpenCVE AI on August 22, 2026 at 14:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Greenshift to a version newer than 12.8.9, which removes the vulnerable function.
  • If an immediate upgrade is not possible, temporarily disable or deactivate the Greenshift plugin to prevent the malicious function from being called.
  • Revoke the "edit_posts" capability from contributor roles or adjust role permissions so that contributors cannot execute the vulnerable function.

Generated by OpenCVE AI on August 22, 2026 at 14:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpsoul
Wpsoul greenshift – Animation And Page Builder Blocks
Vendors & Products Wordpress
Wordpress wordpress
Wpsoul
Wpsoul greenshift – Animation And Page Builder Blocks

Sat, 22 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Description The GreenShift – Animation and Page Builder Blocks plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 12.8.9. This is due to a missing capability check on the 'gspb_update_global_wp_settings' function that only verifies the 'edit_posts' capability instead of requiring administrative privileges. This makes it possible for authenticated attackers, with contributor-level access and above, to modify global WordPress theme color settings site-wide, leading to site defacement.
Title Greenshift <= 12.8.9 - Authenticated (Contributor+) Theme Settings Modification via 'gspb_update_global_wp_settings'
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
Wpsoul Greenshift – Animation And Page Builder Blocks
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-08-22T13:27:15.792Z

Reserved: 2026-03-29T04:54:52.335Z

Link: CVE-2026-5093

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-22T14:16:33.210

Modified: 2026-08-22T14:16:33.210

Link: CVE-2026-5093

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T14:30:17Z

Weaknesses