Stored Cross-Site Scripting in Greenshift Animation and Page Builder for WordPress
CVE-2025-11841 
6.4MEDIUM
Key Information:
- Vendor
 WordPress
- Vendor
 - CVE Published:
 - 4 November 2025
 
What is CVE-2025-11841?
The Greenshift plugin for WordPress is susceptible to stored cross-site scripting (XSS) due to inadequate input sanitization and output escaping. This vulnerability allows authenticated users with Contributor-level access and higher to inject malicious web scripts through Chart Data attributes. When a page containing such an injection is accessed, the malicious script executes, potentially compromising users' data and site integrity.
Affected Version(s)
Greenshift – animation and page builder blocks * <= 12.2.7