Impact
The Greenshift – animation and page builder blocks plugin for WordPress allows unauthenticated attackers to inject arbitrary JavaScript by using the {{GET:…}} dynamic placeholder inside the Custom JS field of an element block. When a user clicks a crafted link and the placeholder value is substituted, the plugin echoes the value into an unescaped <script type="module"> tag, causing the script to execute in that user’s browser. The vulnerability can compromise confidentiality, integrity, and availability by enabling data theft, session hijacking, or defacement from the victim’s session.
Affected Systems
WordPress sites that have installed Greenshift plugin version 13.2.0 or earlier and have configured an element block's Custom JS field to use a {{GET:…}} placeholder. Any site publisher using these configurations is affected.
Risk and Exploitability
The CVSS score of 6.1 classifies this flaw as moderately severe. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting that exploit activity has not been reported publicly yet. However, the condition that the site admin must have added a GET placeholder and the keyword "import" to the JavaScript is a specific configuration requirement. If a site satisfies those prerequisites, the attacker can supply a malicious payload in the query string, leading to reflected XSS without requiring authentication. This narrows the exploitable attack surface but still poses a significant risk to all users who interact with the affected page.
OpenCVE Enrichment