Insecure Direct Object Reference in Greenshift Animation and Page Builder Blocks for WordPress
CVE-2026-2371
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 March 2026
What is CVE-2026-2371?
The Greenshift Animation and Page Builder Blocks plugin for WordPress has a vulnerability that allows unauthenticated users to access sensitive content. The issue arises from a misspecified AJAX handler, gspb_el_reusable_load(), which fails to validate user permissions and post status when processing requests for specific block content. As a result, any user can exploit the vulnerability to retrieve HTML content from private, draft, or password-protected blocks via an arbitrary post_id, exposing crucial elements of the site and compromising content security.
Affected Version(s)
Greenshift β animation and page builder blocks 0 <= 12.8.3