Impact
The Greenshift WordPress plugin up to version 13.1.x does not escape a block animation attribute before outputting it within an HTML attribute. As a result, users with contributor-level access or higher can embed arbitrary JavaScript code. The code is stored with the content and executes every time a visitor loads the page.
Affected Systems
Any WordPress site that has the Greenshift plugin installed with a version older than 13.2.0 is affected. The vendor is listed as Unknown:Greenshift. The vulnerability exists solely within the plugin; no other server components are involved.
Risk and Exploitability
An attacker needs only contributor permissions to inject the payload; once stored, the code runs in every viewer’s browser. The EPSS score is not publicly available and the issue is not listed in the CISA KEV catalog. Because the vulnerability is based on a stored client‑side flaw, the risk arises when the content is accessed by users. No publicly available exploit has been released, so the immediate risk depends on how many sites allow contributor access to create content.
OpenCVE Enrichment