VYPR

Greenshift

by WordPress

Source repositories

CVEs (7)

  • CVE-2023-6636HigJan 11, 2024
    risk 0.40cvss 7.2epss 0.01

    The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on the 'gspb_save_files' function in versions up to, and including, 7.6.2. This makes it possible for authenticated attackers…

  • CVE-2025-3616Apr 22, 2025
    risk 0.00cvss epss 0.02

    The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the gspb_make_proxy_api_request() function in versions 11.4 to 11.4.5. This makes it possible for authenticated attackers,…

  • CVE-2024-6155Jan 9, 2025
    risk 0.00cvss epss 0.00

    The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Authenticated (Subscriber+) Server-Side Request Forgery and Stored Cross Site Scripting in all versions up to, and including, 9.0.0 due to a missing capability check in the…

  • CVE-2024-11181Dec 12, 2024
    risk 0.00cvss epss 0.00

    The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 9.9.9.3 via the 'wp_reusable_render' shortcode due to insufficient restrictions on which posts can be included. This makes it…

  • CVE-2023-22707Mar 27, 2023
    risk 0.00cvss epss 0.00

    Auth. (author+) Cross-Site Scripting (XSS) vulnerability in Wpsoul Greenshift – animation and page builder blocks plugin <= 4.9.9 versions.

  • CVE-2023-0378Feb 21, 2023
    risk 0.00cvss epss 0.01

    The Greenshift WordPress plugin before 5.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

  • CVE-2022-4653Jan 16, 2023
    risk 0.00cvss epss 0.00

    The Greenshift WordPress plugin before 4.8.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.