CVE-2026-93880
Received Received - Intake

Reflected Cross-Site Scripting in Greenshift WordPress Plugin

Vulnerability report for CVE-2026-93880, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Wordfence

Description

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via '{{GET:}}' Dynamic Placeholder in all versions up to, and including, 13.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This requires a site administrator to have configured an element block's Custom JS field to include a {{GET:...}} placeholder and for that JS to contain the token 'import', which routes the substituted value to the unescaped raw echo branch inside a <script type="module"> tag.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
greenshift animation_and_page_builder_blocks_plugin to 13.2.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This WordPress plugin vulnerability allows unauthenticated attackers to inject malicious scripts via a reflected Cross-Site Scripting (XSS) flaw. It occurs when a site administrator configures a Custom JS field with a {{GET:...}} placeholder containing the word 'import', which then executes unescaped code in a script tag when a user clicks a crafted link.

Detection Guidance

To detect this vulnerability, inspect WordPress sites using the Greenshift plugin for versions up to 13.2.0. Check if Custom JS fields in element blocks contain {{GET:...}} placeholders with the token 'import'. Review server logs for unusual script injections or unescaped outputs in <script type="module"> tags.

Impact Analysis

An attacker could steal user sessions, redirect to malicious sites, or perform actions on your behalf. It requires tricking a user into clicking a link, but no authentication is needed for the attack itself.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating GDPR's integrity and confidentiality requirements or HIPAA's safeguards for protected health information. Organizations may face compliance penalties if exploited.

Mitigation Strategies

Immediately update the Greenshift plugin to the latest version beyond 13.2.0. Remove any {{GET:...}} placeholders from Custom JS fields in element blocks. Disable or restrict access to untrusted users for JS configuration fields. Monitor for suspicious activity or unauthorized script executions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93880. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart