Description
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via '{{GET:}}' Dynamic Placeholder in all versions up to, and including, 13.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This requires a site administrator to have configured an element block's Custom JS field to include a {{GET:...}} placeholder and for that JS to contain the token 'import', which routes the substituted value to the unescaped raw echo branch inside a <script type="module"> tag.
Published: 2026-10-02
Score: 6.1 Medium
EPSS: n/a
KEV: No
Impact: Reflected Cross‑Site Scripting (XSS)
Action: Apply patch
AI Analysis

Impact

The Greenshift – animation and page builder blocks plugin for WordPress allows unauthenticated attackers to inject arbitrary JavaScript by using the {{GET:…}} dynamic placeholder inside the Custom JS field of an element block. When a user clicks a crafted link and the placeholder value is substituted, the plugin echoes the value into an unescaped <script type="module"> tag, causing the script to execute in that user’s browser. The vulnerability can compromise confidentiality, integrity, and availability by enabling data theft, session hijacking, or defacement from the victim’s session.

Affected Systems

WordPress sites that have installed Greenshift plugin version 13.2.0 or earlier and have configured an element block's Custom JS field to use a {{GET:…}} placeholder. Any site publisher using these configurations is affected.

Risk and Exploitability

The CVSS score of 6.1 classifies this flaw as moderately severe. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting that exploit activity has not been reported publicly yet. However, the condition that the site admin must have added a GET placeholder and the keyword "import" to the JavaScript is a specific configuration requirement. If a site satisfies those prerequisites, the attacker can supply a malicious payload in the query string, leading to reflected XSS without requiring authentication. This narrows the exploitable attack surface but still poses a significant risk to all users who interact with the affected page.

Generated by OpenCVE AI on October 2, 2026 at 08:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Greenshift to the latest version that removes the unsafe dynamic placeholder handling.
  • If an upgrade is not possible, disable the Custom JS field or remove any {{GET:…}} placeholders from existing blocks.
  • Implement a strict Content Security Policy that disallows inline scripts and restricts script loading to trusted origins to mitigate the impact of any residual XSS.

Generated by OpenCVE AI on October 2, 2026 at 08:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Description The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via '{{GET:}}' Dynamic Placeholder in all versions up to, and including, 13.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This requires a site administrator to have configured an element block's Custom JS field to include a {{GET:...}} placeholder and for that JS to contain the token 'import', which routes the substituted value to the unescaped raw echo branch inside a &lt;script type="module"&gt; tag.
Title Greenshift <= 13.2.0 - Reflected Cross-Site Scripting via '{{GET:}}' Dynamic Placeholder
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-02T07:39:21.782Z

Reserved: 2026-09-18T20:04:24.168Z

Link: CVE-2026-93880

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T08:17:03.413

Modified: 2026-10-02T08:17:03.413

Link: CVE-2026-93880

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T08:45:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')