Stored Cross-Site Scripting in GreenShift Animation and Page Builder Blocks Plugin for WordPress
CVE-2026-4895
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 April 2026
What is CVE-2026-4895?
The GreenShift Animation and Page Builder Blocks plugin for WordPress is susceptible to Stored Cross-Site Scripting due to insufficient input sanitization and output escaping within the gspb_greenShift_block_script_assets() function. When processing HTML string replacements for images, authenticated users with contributor-level access can inject arbitrary web scripts into page attributes. This occurs because the str_replace() function fails to properly parse the HTML, allowing the introduction of malicious JavaScript payloads. As a result, any user visiting the compromised page could unknowingly execute the injected scripts.
Affected Version(s)
Greenshift β animation and page builder blocks 0 <= 12.8.9