CVE-2026-5093
Received Received - Intake

Unauthorized Data Modification in GreenShift WordPress Plugin

Vulnerability report for CVE-2026-5093, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-22

Last updated on: 2026-08-22

Assigner: Wordfence

Description

The GreenShift – Animation and Page Builder Blocks plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 12.8.9. This is due to a missing capability check on the 'gspb_update_global_wp_settings' function that only verifies the 'edit_posts' capability instead of requiring administrative privileges. This makes it possible for authenticated attackers, with contributor-level access and above, to modify global WordPress theme color settings site-wide, leading to site defacement.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-22
Last Modified
2026-08-22
Generated
2026-08-22
AI Q&A
2026-08-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
greenshift animation_and_page_builder_blocks to 12.8.9 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The GreenShift – Animation and Page Builder Blocks plugin for WordPress has a vulnerability in versions up to 12.8.9. It allows unauthorized modification of data due to a missing capability check. The function 'gspb_update_global_wp_settings' only checks for the 'edit_posts' capability instead of requiring admin privileges. This lets authenticated attackers with contributor-level access or higher change global WordPress theme color settings across the entire site, potentially defacing it.

Detection Guidance

Check for unauthorized modifications to WordPress theme color settings or global configurations. Review user roles with contributor-level access or higher for suspicious activity. Inspect plugin versions to confirm if GreenShift – Animation and Page Builder Blocks is version 12.8.9 or lower.

Impact Analysis

If you use the vulnerable plugin, attackers with contributor-level access or higher could modify your site's global theme colors. This could lead to unauthorized changes in appearance, site defacement, or disruption of normal site functionality. The impact is limited to theme settings and does not directly expose sensitive data.

Compliance Impact

This vulnerability does not directly impact compliance with GDPR, HIPAA, or similar regulations since it does not involve unauthorized data access or disclosure. However, site defacement could indirectly affect compliance if it disrupts data integrity or availability, depending on the context of the site and its data handling practices.

Mitigation Strategies

Update the GreenShift plugin to the latest version beyond 12.8.9. Remove or restrict contributor-level access to users who do not require it. Monitor site settings for unauthorized changes and audit user permissions regularly.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-5093. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart